PostgreSQL ODBC driver buffer overflow

postgresql-odbc-bo (16329) The risk level is classified as LowLow Risk

Description:

PostgreSQL is vulnerable to a buffer overflow. A remote attacker could send a PHP script using the php4-odbc driver to overflow a buffer and cause the system to crash.

Note: This vulnerability does not affect other areas of PostgreSQL.


Consequences:

Denial of Service

Remedy:

For Debian GNU/Linux 3.0 (woody):
Upgrade to the latest postgresql package (7.2.1-2woody5 or later), as listed in DSA-516-1. See References.

For Mandrake Linux:
Upgrade to the latest postgresql package, as listed below. Refer to MandrakeSoft Security Advisory MDKSA-2004:072 : postgresql for more information.See References.

Mandrake Linux Corporate Server 2.1: 7.2.2-1.4.C21mdk or later

For other distributions:
Contact your vendor for upgrade or patch information.

References:

  • PostgreSQL Inc. Web site: PostgreSQL Incorporated.
  • BID-10470: PostgreSQL ODBC Driver Unspecified Remote Buffer Overflow Vulnerability
  • CVE-2004-0547: Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash).
  • DSA-516: postgresql -- buffer overflow
  • MDKSA-2004:072: Updated postgresql packages fix buffer overflow in odbc driver

Platforms Affected:

  • Debian Debian Linux 3.0
  • MandrakeSoft Mandrake Linux Corporate Server 2.1 X86_64
  • MandrakeSoft Mandrake Linux Corporate Server 2.1
  • PostgreSQL PostgreSQL 7.2.1

Reported:

Jun 07, 2004

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page