Summary: | <dev-db/postgresql-server-{9.3.3,9.2.7,9.1.12,9.0.16,8.4.20}: Multiple Vulnerabilities (CVE-2014-{0060,0061,0062,0063,0064,0065,0066,2669}) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Aaron W. Swenson <titanofold> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | pgsql-bugs |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://wiki.postgresql.org/wiki/20140220securityrelease | ||
Whiteboard: | B1 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Aaron W. Swenson
![]() + 21 Feb 2014; Patrick Lauer <patrick@gentoo.org> + +postgresql-server-8.4.20.ebuild, +postgresql-server-9.0.16.ebuild, + +postgresql-server-9.1.12.ebuild, +postgresql-server-9.2.7.ebuild, + +postgresql-server-9.3.3.ebuild: + Bump for #501946 All ebuilds in place. Full list of files to stable: =dev-db/postgresql-docs-8.4.20 =dev-db/postgresql-docs-9.0.16 =dev-db/postgresql-docs-9.1.12 =dev-db/postgresql-docs-9.2.7 =dev-db/postgresql-docs-9.3.3 =dev-db/postgresql-base-8.4.20 =dev-db/postgresql-base-9.0.16 =dev-db/postgresql-base-9.1.12 =dev-db/postgresql-base-9.2.7 =dev-db/postgresql-base-9.3.3 =dev-db/postgresql-server-8.4.20 =dev-db/postgresql-server-9.0.16 =dev-db/postgresql-server-9.1.12 =dev-db/postgresql-server-9.2.7 =dev-db/postgresql-server-9.3.3 amd64 stable x86 stable ppc stable ppc64 stable Stable for HPPA. alpha stable > CVE-2014-0061 PostgreSQL: Privilege escalation via explicit calls to validator > functions
I'd say to set it to B1, why it has been set to C3??
arm stable ia64 stable (In reply to Agostino Sarubbo from comment #9) > > CVE-2014-0061 PostgreSQL: Privilege escalation via explicit calls to validator > functions > > I'd say to set it to B1, why it has been set to C3?? Because no one has been successful in escalating their privileges just yet (at least, from what I've been able to discover), and if they were, they'd only be escalated within the database. sparc stable. Maintainer(s), please cleanup. Security, please vote. (In reply to Aaron W. Swenson from comment #12) > Because no one has been successful in escalating their privileges just yet > (at least, from what I've been able to discover), and if they were, they'd > only be escalated within the database. I don't guess this is the right interpretation. It is described to be a privilege escalation. I don't care if someone ha produced a real POC or not. From https://bugzilla.redhat.com/show_bug.cgi?id=1082154 : Common Vulnerabilities and Exposures assigned an identifier CVE-2014-2669 to the following vulnerability: Name: CVE-2014-2669 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2669 Assigned: 20140328 Reference: http://wiki.postgresql.org/wiki/20140220securityrelease Reference: http://www.postgresql.org/about/news/1506/ Reference: http://www.postgresql.org/support/security/ Reference: https://github.com/postgres/postgres/commit/31400a673325147e1205326008e32135a78b4d8a Reference: DEBIAN:DSA-2864 Reference: http://www.debian.org/security/2014/dsa-2864 Reference: DEBIAN:DSA-2865 Reference: http://www.debian.org/security/2014/dsa-2865 Multiple integer overflows in contrib/hstore/hstore_io.c in PostgreSQL 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact via vectors related to the (1) hstore_recv, (2) hstore_from_arrays, and (3) hstore_from_array functions in contrib/hstore/hstore_io.c; and the (4) hstoreArrayToPairs function in contrib/hstore/hstore_op.c, which triggers a buffer overflow. NOTE: this issue was SPLIT from CVE-2014-0064 because it has a different set of affected versions. CVE-2014-2669 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-2669): Multiple integer overflows in contrib/hstore/hstore_io.c in PostgreSQL 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact via vectors related to the (1) hstore_recv, (2) hstore_from_arrays, and (3) hstore_from_array functions in contrib/hstore/hstore_io.c; and the (4) hstoreArrayToPairs function in contrib/hstore/hstore_op.c, which triggers a buffer overflow. NOTE: this issue was SPLIT from CVE-2014-0064 because it has a different set of affected versions. CVE-2014-0066 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0066): The chkpass extension in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly check the return value of the crypt library function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors. CVE-2014-0065 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0065): Multiple buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact and attack vectors, a different vulnerability than CVE-2014-0063. CVE-2014-0064 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0064): Multiple integer overflows in the path_in and other unspecified functions in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact and attack vectors, which trigger a buffer overflow. NOTE: this identifier has been SPLIT due to different affected versions; use CVE-2014-2669 for the hstore vector. CVE-2014-0063 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0063): Multiple stack-based buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via vectors related to an incorrect MAXDATELEN constant and datetime values involving (1) intervals, (2) timestamps, or (3) timezones, a different vulnerability than CVE-2014-0065. CVE-2014-0062 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0062): Race condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE commands in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allows remote authenticated users to create an unauthorized index or read portions of unauthorized tables by creating or deleting a table with the same name during the timing window. CVE-2014-0061 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0061): The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to gain privileges via a function that is (1) defined in another language or (2) not allowed to be directly called by the user due to permissions. CVE-2014-0060 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0060): PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly enforce the ADMIN OPTION restriction, which allows remote authenticated members of a role to add or remove arbitrary users to that role by calling the SET ROLE command before the associated GRANT command. Arches and Mainter(s), Thank you for your work. Added to an existing GLSA request. This issue was resolved and addressed in GLSA 201408-15 at http://security.gentoo.org/glsa/glsa-201408-15.xml by GLSA coordinator Kristian Fiskerstrand (K_F). |