Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 152783 - dev-db/postgresql: DoS vulnerability if authenticated (CVE-2006-5540?)
Summary: dev-db/postgresql: DoS vulnerability if authenticated (CVE-2006-5540?)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://www.postgresql.org/about/news.664
Whiteboard: B/C3 [noglsa] Falco
Keywords:
Depends on:
Blocks:
 
Reported: 2006-10-25 06:53 UTC by Raphael Marichez (Falco) (RETIRED)
Modified: 2019-12-29 11:12 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-10-25 06:53:38 UTC
Hello postgreSQL team, a little DoS vulnerability with the corrected versions below:

Posted on 2006-10-16
Posted by josh@postgresql.org

The PostgreSQL project today is releasing the following minor versions, which fix three different crash vulnerabilities as well as an assortment of minor issues. Users of all PostgreSQL versions are urged to upgrade at the earliest opportunity.

The versions being released are: 8.1.5, 8.0.9, 7.4.14, 7.3.16. These are cumulative patch releases which simply replace the PostgreSQL binaries for major versions 8.1, 8.0, 7.4 and 7.3. Note that users of versions 7.4.0, 7.4.1, 8.0.0 and 8.0.1 may have to take additional steps in the course of upgrading -- see the release notes for details.

Release Notes
Download

The three crash conditions are not considered critical vulnerabilities, because all three require authenticated access to the database with the ability to run ad-hoc queries, and none can be exploited for privilege escalation. As a result, we have NOT filed a CVE for these issues.

Source for these releases is currently available, as well as binaries for Windows and some distributions of Linux. Binaries for Solaris, other Linuxen, and OSX should be obtained from their respective vendors.
Comment 1 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-11-03 06:05:06 UTC
chtekk or dev-zero any news here? please advise
Comment 2 Tiziano Müller (RETIRED) gentoo-dev 2006-11-04 02:09:15 UTC
Sorry for the delay. I think that we can release the version bump this weekend.

We (chtekk and I) have to decide whether and how some improvements of the ebuilds we have in the overlay should be back-ported to the ebuilds in the tree for the new version.

After the version bump, I'll open a stabilization-bug with the request to stable the new postgresql-versions within 7-10 days. This is a reasonable duration since it's not a critical vulnerability and should be manageable by the arch-teams.
Comment 3 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-11-04 04:35:15 UTC
(In reply to comment #2)
> Sorry for the delay. I think that we can release the version bump this weekend.

thanks

> 
> We (chtekk and I) have to decide whether and how some improvements of the
> ebuilds we have in the overlay should be back-ported to the ebuilds in the tree
> for the new version.

as you want :)



> After the version bump, I'll open a stabilization-bug with the request to
> stable the new postgresql-versions within 7-10 days. This is a reasonable
> duration since it's not a critical vulnerability and should be manageable by
> the arch-teams.

yes OK


Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-11-20 23:19:34 UTC
Pulling in herd for advise.
Comment 5 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-12-14 03:05:47 UTC
Hi arches, please remove yourself from the Cc: list when you stabilize the targetted versions, as usual.

Target keywords are:

8.0.9(-r1)?  on all Cced arches (the maintainer wishes 8.0.9-r1)
7.4.14 on all Cced arches
7.3.16 on all Cced arches except PPC64


8.1.15 is not needed in the security scope.

There's a dependency with dev-db/libpq, see bug 158075.
Comment 6 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-12-14 03:06:30 UTC
removing X86 from Cc for our statistics, sorry for the spam :)
Comment 7 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-12-14 10:07:22 UTC
*** Bug 158075 has been marked as a duplicate of this bug. ***
Comment 8 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-12-14 10:09:54 UTC
Arches everything is handled here now:

dev-db/postgresql:
8.0.9-r1  on all Cced arches
7.4.14 on all Cced arches
7.3.16 on all Cced arches except PPC64

and dev-db/libpq  as a dependency

thanks
Comment 9 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-12-14 10:10:56 UTC
spam, spam...
Comment 10 Markus Rothe (RETIRED) gentoo-dev 2006-12-14 12:16:06 UTC
ppc64 stable
Comment 11 Tobias Scherbaum (RETIRED) gentoo-dev 2006-12-17 00:09:30 UTC
ppc stable
Comment 12 Jason Wever (RETIRED) gentoo-dev 2006-12-17 10:12:03 UTC
SPARC stable
Comment 13 Bryan Østergaard (RETIRED) gentoo-dev 2006-12-17 13:03:20 UTC
Stable on Alpha + ia64.
Comment 14 Konstantin Arkhipov (RETIRED) gentoo-dev 2006-12-17 13:37:49 UTC
amd64 stable.
Comment 15 René Nussbaumer (RETIRED) gentoo-dev 2006-12-17 14:04:55 UTC
stable on hppa.
Comment 16 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-12-17 15:19:53 UTC
(In reply to comment #12)
> SPARC stable
> 

hi Jason,

postgresql-7.3.16 seems to be missing: is it expected?

Comment 17 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-12-17 15:20:54 UTC
Security team: Time To Vote

I vote no because of the needed authentication before triggering the DoS
Comment 18 Jason Wever (RETIRED) gentoo-dev 2006-12-17 18:58:28 UTC
Looks like I goofed on 7.3.16.  It's fixed now.  Thanks.
Comment 19 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-12-17 22:17:50 UTC
I tend to vote NO.
Comment 20 Wolf Giesen (RETIRED) gentoo-dev 2006-12-17 22:41:43 UTC
Not sure about this one. Authentication is no real criteria IMHO, since every stupid webabb uses an authenticated connection. Unless somebody can enlighten me on the exact requirement to exploit this I tend to vote YES.
Comment 21 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-12-28 09:04:07 UTC
closing with noglsa since there wasn't any "Yes". Feel free to reopen if you disagree.

As usual, arm, mips, s390 and sh, don't forget to mark stable the new version at your convenience.