Executive Summary
Summary | |
---|---|
Title | Red Hat Application Stack v2.3 security and enhancement update |
Informations | |||
---|---|---|---|
Name | RHSA-2009:1067 | First vendor Publication | 2009-05-26 |
Vendor | RedHat | Last vendor Modification | 2009-05-26 |
Severity (Vendor) | Moderate | Revision | 01 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Problem Description: Red Hat Application Stack v2.3 is now available. This update fixes several security issues and adds various enhancements. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Application Stack v2 for Enterprise Linux (v.5) - i386, x86_64 3. Description: Red Hat Application Stack v2.3 is an integrated open source application stack, that includes Red Hat Enterprise Linux 5 and JBoss Enterprise Application Platform (EAP). JBoss EAP is provided through the JBoss EAP channels on the Red Hat Network. This update fixes the following security issues: A heap-based buffer overflow flaw was discovered in the perl-DBD-Pg pg_getline function implementation. If the pg_getline or getline functions read large, untrusted records from a database, it could cause an application using these functions to crash or, possibly, execute arbitrary code. (CVE-2009-0663) Note: After installing this update, pg_getline may return more data than specified by its second argument, as this argument will be ignored. This is consistent with current upstream behavior. Previously, the length limit (the second argument) was not enforced, allowing a buffer overflow. A memory leak flaw was found in the perl-DBD-Pg function performing the de-quoting of BYTEA type values acquired from a database. An attacker able to cause an application using perl-DBD-Pg to perform a large number of SQL queries returning BYTEA records, could cause the application to use excessive amounts of memory or, possibly, crash. (CVE-2009-1341) MySQL was updated to version 5.0.79, fixing the following security issues: A flaw was found in the way MySQL handles an empty bit-string literal. A remote, authenticated attacker could crash the MySQL server daemon (mysqld) if they used an empty bit-string literal in an SQL statement. This issue only caused a temporary denial of service, as the MySQL daemon was automatically restarted after the crash. (CVE-2008-3963) It was discovered that the Red Hat Security Advisory RHSA-2008:0505, for Red Hat Application Stack v2.1, provided an incomplete fix for the flaw where MySQL did not correctly check directories used as arguments for the DATA DIRECTORY and INDEX DIRECTORY directives. Using this flaw, an authenticated attacker could elevate their access privileges to tables created by other database users. Note: This attack does not work on existing tables. An attacker can only elevate their access to another user's tables as the tables are created. As well, the names of these created tables need to be predicted correctly for this attack to succeed. (CVE-2008-4098) PostgreSQL was updated to version 8.2.13, fixing the following security issue: A flaw was found in the way PostgreSQL handles encoding conversion. A remote, authenticated user could trigger an encoding conversion failure, possibly leading to a temporary denial of service. (CVE-2009-0922) Also, the following packages have been updated: * httpd to 2.2.11 * mysql-connector-odbc to 3.51.27r695 * perl-DBD-MySQL to 4.010-1.el5s2 * php to 5.2.9 * postgresql-jdbc to 8.2.509 * postgresqlclient81 to 8.1.17 All users should upgrade to these updated packages, which resolve these issues. Users must restart the individual services, including postgresql, mysqld, and httpd, for this update to take effect. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at http://kbase.redhat.com/faq/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 454077 - CVE-2008-4098 mysql: incomplete upstream fix for CVE-2008-2079 462071 - CVE-2008-3963 MySQL: Using an empty binary value leads to server crash 488156 - CVE-2009-0922 postgresql: potential DoS due to conversion functions 497367 - CVE-2009-0663 perl-DBD-Pg: pg_getline buffer overflow 497503 - CVE-2009-1341 perl-DBD-Pg: dequote_bytea memory leak |
Original Source
Url : https://rhn.redhat.com/errata/RHSA-2009-1067.html |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
17 % | CWE-399 | Resource Management Errors |
17 % | CWE-264 | Permissions, Privileges, and Access Controls |
17 % | CWE-200 | Information Exposure |
17 % | CWE-134 | Uncontrolled Format String (CWE/SANS Top 25) |
17 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
17 % | CWE-59 | Improper Link Resolution Before File Access ('Link Following') |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:10133 | |||
Oval ID: | oval:org.mitre.oval:def:10133 | ||
Title: | MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are within the MySQL home data directory, which can point to tables that are created in the future. | ||
Description: | MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are within the MySQL home data directory, which can point to tables that are created in the future. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2008-2079 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:10521 | |||
Oval ID: | oval:org.mitre.oval:def:10521 | ||
Title: | MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote attackers to cause a denial of service (daemon crash) by using this token in a SQL statement. | ||
Description: | MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote attackers to cause a denial of service (daemon crash) by using this token in a SQL statement. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2008-3963 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:10591 | |||
Oval ID: | oval:org.mitre.oval:def:10591 | ||
Title: | MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097. | ||
Description: | MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2008-4098 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:13702 | |||
Oval ID: | oval:org.mitre.oval:def:13702 | ||
Title: | DSA-1780-1 libdbd-pg-perl -- several | ||
Description: | Two vulnerabilities have been discovered in libdbd-pg-perl, the DBI driver module for PostgreSQL database access. CVE-2009-0663 A heap-based buffer overflow may allow attackers to execute arbitrary code through applications which read rows from the database using the pg_getline and getline functions. CVE-2009-1341 A memory leak in the routine which unquotes BYTEA values returned from the database allows attackers to cause a denial of service. For the old stable distribution, these problems have been fixed in version 1.49-2+etch1. For the stable distribution and the unstable distribution, these problems have been fixed in version 2.1.3-1 before the release of lenny. We recommend that you upgrade your libdbd-pg-perl package. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1780-1 CVE-2009-0663 CVE-2009-1341 | Version: | 5 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | libdbd-pg-perl |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:16963 | |||
Oval ID: | oval:org.mitre.oval:def:16963 | ||
Title: | USN-671-1 -- mysql-dfsg-5.0 vulnerabilities | ||
Description: | It was discovered that MySQL could be made to overwrite existing table files in the data directory. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-671-1 CVE-2008-2079 CVE-2008-4097 CVE-2008-4098 CVE-2008-3963 | Version: | 7 |
Platform(s): | Ubuntu 6.06 Ubuntu 7.10 Ubuntu 8.04 | Product(s): | mysql-dfsg-5.0 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:18619 | |||
Oval ID: | oval:org.mitre.oval:def:18619 | ||
Title: | DSA-1608-1 mysql-dfsg-5.0 - authorisation bypass | ||
Description: | Sergei Golubchik discovered that MySQL, a widely-deployed database server, did not properly validate optional data or index directory paths given in a CREATE TABLE statement, nor would it (under proper conditions) prevent two databases from using the same paths for data or index files. This permits an authenticated user with authorisation to create tables in one database to read, write or delete data from tables subsequently created in other databases, regardless of other GRANT authorisations. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1608-1 CVE-2008-2079 | Version: | 7 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | mysql-dfsg-5.0 |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:22850 | |||
Oval ID: | oval:org.mitre.oval:def:22850 | ||
Title: | ELSA-2009:0479: perl-DBD-Pg security update (Moderate) | ||
Description: | Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-dependent attackers to cause a denial of service (memory consumption) by fetching data with BYTEA columns. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2009:0479-01 CVE-2009-0663 CVE-2009-1341 | Version: | 13 |
Platform(s): | Oracle Linux 5 | Product(s): | perl-DBD-Pg |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:29079 | |||
Oval ID: | oval:org.mitre.oval:def:29079 | ||
Title: | RHSA-2009:0479 -- perl-DBD-Pg security update (Moderate) | ||
Description: | An updated perl-DBD-Pg package that fixes two security issues is now available for Red Hat Enterprise Linux 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team. Perl DBI is a database access Application Programming Interface (API) for the Perl language. perl-DBD-Pg allows Perl applications to access PostgreSQL database servers. A heap-based buffer overflow flaw was discovered in the pg_getline function implementation. If the pg_getline or getline functions read large, untrusted records from a database, it could cause an application using these functions to crash or, possibly, execute arbitrary code. (CVE-2009-0663) | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2009:0479 CESA-2009:0479-CentOS 5 CVE-2009-0663 CVE-2009-1341 | Version: | 3 |
Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 | Product(s): | perl-DBD-Pg |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:6252 | |||
Oval ID: | oval:org.mitre.oval:def:6252 | ||
Title: | Security Vulnerability in PostgreSQL Shipped with Solaris may Allow a Denial of Service (DoS) | ||
Description: | PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2009-0922 | Version: | 1 |
Platform(s): | Sun Solaris 10 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:7917 | |||
Oval ID: | oval:org.mitre.oval:def:7917 | ||
Title: | DSA-1608 mysql-dfsg-5.0 -- authorisation bypass | ||
Description: | Sergei Golubchik discovered that MySQL, a widely-deployed database server, did not properly validate optional data or index directory paths given in a CREATE TABLE statement, nor would it (under proper conditions) prevent two databases from using the same paths for data or index files. This permits an authenticated user with authorisation to create tables in one database to read, write or delete data from tables subsequently created in other databases, regardless of other GRANT authorisations. The Common Vulnerabilities and Exposures project identifies this weakness as CVE-2008-2079. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1608 CVE-2008-2079 | Version: | 3 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | mysql-dfsg-5.0 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:8139 | |||
Oval ID: | oval:org.mitre.oval:def:8139 | ||
Title: | DSA-1780 libdbd-pg-perl -- several vulnerabilities | ||
Description: | Two vulnerabilities have been discovered in libdbd-pg-perl, the DBI driver module for PostgreSQL database access (DBD::Pg). A heap-based buffer overflow may allow attackers to execute arbitrary code through applications which read rows from the database using the pg_getline and getline functions. (More common retrieval methods, such as selectall_arrayref and fetchrow_array, are not affected.) A memory leak in the routine which unquotes BYTEA values returned from the database allows attackers to cause a denial of service. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1780 CVE-2009-0663 CVE-2009-1341 | Version: | 3 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | libdbd-pg-perl |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:9499 | |||
Oval ID: | oval:org.mitre.oval:def:9499 | ||
Title: | Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-dependent attackers to execute arbitrary code via unspecified input to an application that uses the getline and pg_getline functions to read database rows. | ||
Description: | Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-dependent attackers to execute arbitrary code via unspecified input to an application that uses the getline and pg_getline functions to read database rows. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2009-0663 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 | Product(s): | |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:9680 | |||
Oval ID: | oval:org.mitre.oval:def:9680 | ||
Title: | Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-dependent attackers to cause a denial of service (memory consumption) by fetching data with BYTEA columns. | ||
Description: | Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-dependent attackers to cause a denial of service (memory consumption) by fetching data with BYTEA columns. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2009-1341 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 | Product(s): | |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2012-03-16 | Name : Ubuntu Update for mysql-5.1 USN-1397-1 File : nvt/gb_ubuntu_USN_1397_1.nasl |
2012-02-12 | Name : Gentoo Security Advisory GLSA 201201-02 (MySQL) File : nvt/glsa_201201_02.nasl |
2012-02-12 | Name : Gentoo Security Advisory GLSA 201110-22 (postgresql-server postgresql-base) File : nvt/glsa_201110_22.nasl |
2011-08-09 | Name : CentOS Update for mysql CESA-2010:0109 centos5 i386 File : nvt/gb_CESA-2010_0109_mysql_centos5_i386.nasl |
2011-08-09 | Name : CentOS Update for postgresql CESA-2009:1484 centos5 i386 File : nvt/gb_CESA-2009_1484_postgresql_centos5_i386.nasl |
2011-08-09 | Name : CentOS Update for postgresql CESA-2009:1484 centos4 i386 File : nvt/gb_CESA-2009_1484_postgresql_centos4_i386.nasl |
2011-08-09 | Name : CentOS Update for mysql CESA-2009:1289 centos5 i386 File : nvt/gb_CESA-2009_1289_mysql_centos5_i386.nasl |
2011-08-09 | Name : CentOS Update for perl-DBD-Pg CESA-2009:0479 centos5 i386 File : nvt/gb_CESA-2009_0479_perl-DBD-Pg_centos5_i386.nasl |
2010-05-12 | Name : Mac OS X Security Update 2008-007 File : nvt/macosx_secupd_2008-007.nasl |
2010-05-12 | Name : Mac OS X Security Update 2009-005 File : nvt/macosx_secupd_2009-005.nasl |
2010-02-19 | Name : RedHat Update for mysql RHSA-2010:0110-01 File : nvt/gb_RHSA-2010_0110-01_mysql.nasl |
2010-02-19 | Name : CentOS Update for mysql CESA-2010:0110 centos4 i386 File : nvt/gb_CESA-2010_0110_mysql_centos4_i386.nasl |
2010-02-19 | Name : RedHat Update for mysql RHSA-2010:0109-01 File : nvt/gb_RHSA-2010_0109-01_mysql.nasl |
2010-02-15 | Name : Ubuntu Update for MySQL vulnerabilities USN-897-1 File : nvt/gb_ubuntu_USN_897_1.nasl |
2010-01-19 | Name : Mandriva Update for mysql MDVSA-2010:012 (mysql) File : nvt/gb_mandriva_MDVSA_2010_012.nasl |
2010-01-19 | Name : Mandriva Update for mysql MDVSA-2010:011 (mysql) File : nvt/gb_mandriva_MDVSA_2010_011.nasl |
2009-12-30 | Name : Mandriva Security Advisory MDVSA-2009:344 (perl-DBD-Pg) File : nvt/mdksa_2009_344.nasl |
2009-12-10 | Name : Mandriva Security Advisory MDVSA-2009:326 (mysql) File : nvt/mdksa_2009_326.nasl |
2009-10-13 | Name : SLES10: Security update for MySQL File : nvt/sles10_mysql1.nasl |
2009-10-13 | Name : SLES10: Security update for PostgreSQL File : nvt/sles10_postgresql.nasl |
2009-10-13 | Name : CentOS Security Advisory CESA-2009:1484 (postgresql) File : nvt/ovcesa2009_1484.nasl |
2009-10-13 | Name : RedHat Security Advisory RHSA-2009:1484 File : nvt/RHSA_2009_1484.nasl |
2009-10-13 | Name : SLES10: Security update for MySQL File : nvt/sles10_mysql0.nasl |
2009-10-11 | Name : SLES11: Security update for PostgreSQL File : nvt/sles11_postgresql.nasl |
2009-10-10 | Name : SLES9: Security update for PostgreSQL File : nvt/sles9p5047220.nasl |
2009-10-10 | Name : SLES9: Security update for MySQL File : nvt/sles9p5040120.nasl |
2009-10-10 | Name : SLES9: Security update for MySQL File : nvt/sles9p5032620.nasl |
2009-10-06 | Name : Mandrake Security Advisory MDVSA-2009:255 (perl-DBD-Pg) File : nvt/mdksa_2009_255.nasl |
2009-09-21 | Name : CentOS Security Advisory CESA-2009:1289 (mysql) File : nvt/ovcesa2009_1289.nasl |
2009-09-15 | Name : Fedora Core 10 FEDORA-2009-9474 (postgresql) File : nvt/fcore_2009_9474.nasl |
2009-09-09 | Name : RedHat Security Advisory RHSA-2009:1289 File : nvt/RHSA_2009_1289.nasl |
2009-07-06 | Name : SuSE Security Summary SUSE-SR:2009:012 File : nvt/suse_sr_2009_012.nasl |
2009-06-05 | Name : Ubuntu USN-763-1 (xine-lib) File : nvt/ubuntu_763_1.nasl |
2009-06-05 | Name : Ubuntu USN-776-2 (kvm) File : nvt/ubuntu_776_2.nasl |
2009-06-05 | Name : RedHat Security Advisory RHSA-2009:1067 File : nvt/RHSA_2009_1067.nasl |
2009-05-20 | Name : RedHat Security Advisory RHSA-2009:0479 File : nvt/RHSA_2009_0479.nasl |
2009-05-20 | Name : CentOS Security Advisory CESA-2009:0479 (perl-DBD-Pg) File : nvt/ovcesa2009_0479.nasl |
2009-05-05 | Name : Debian Security Advisory DSA 1780-1 (libdbd-pg-perl) File : nvt/deb_1780_1.nasl |
2009-04-28 | Name : Mandrake Security Advisory MDVSA-2009:094 (mysql) File : nvt/mdksa_2009_094.nasl |
2009-04-28 | Name : SuSE Security Summary SUSE-SR:2009:009 File : nvt/suse_sr_2009_009.nasl |
2009-04-24 | Name : PostgreSQL Conversion Encoding Remote Denial of Service Vulnerability File : nvt/postgresql_cve_2009_0922.nasl |
2009-04-23 | Name : MySQL MyISAM Table Privileges Secuity Bypass Vulnerability File : nvt/mysql_29106.nasl |
2009-04-15 | Name : Ubuntu USN-753-1 (postgresql-8.3) File : nvt/ubuntu_753_1.nasl |
2009-04-09 | Name : Mandriva Update for mysql MDVSA-2008:150 (mysql) File : nvt/gb_mandriva_MDVSA_2008_150.nasl |
2009-04-09 | Name : Mandriva Update for mysql MDVSA-2008:149 (mysql) File : nvt/gb_mandriva_MDVSA_2008_149.nasl |
2009-03-31 | Name : Mandrake Security Advisory MDVSA-2009:079 (postgresql) File : nvt/mdksa_2009_079.nasl |
2009-03-31 | Name : Fedora Core 9 FEDORA-2009-2927 (postgresql) File : nvt/fcore_2009_2927.nasl |
2009-03-31 | Name : Fedora Core 10 FEDORA-2009-2959 (postgresql) File : nvt/fcore_2009_2959.nasl |
2009-03-26 | Name : PostgreSQL Denial of Service Vulnerability (Linux) File : nvt/secpod_postgresql_dos_vuln_lin.nasl |
2009-03-23 | Name : Ubuntu Update for mysql-dfsg-5.0 vulnerabilities USN-671-1 File : nvt/gb_ubuntu_USN_671_1.nasl |
2009-03-06 | Name : RedHat Update for mysql RHSA-2008:0768-01 File : nvt/gb_RHSA-2008_0768-01_mysql.nasl |
2009-01-23 | Name : SuSE Update for openwsman SUSE-SA:2008:041 File : nvt/gb_suse_2008_041.nasl |
2009-01-20 | Name : SuSE Security Summary SUSE-SR:2009:001 (OpenSuSE 11.1) File : nvt/suse_sr_2009_001.nasl |
2009-01-20 | Name : SuSE Security Summary SUSE-SR:2009:001 (OpenSuSE 11.0) File : nvt/suse_sr_2009_001a.nasl |
2009-01-20 | Name : SuSE Security Summary SUSE-SR:2009:001 (OpenSuSE 10.3) File : nvt/suse_sr_2009_001b.nasl |
2009-01-13 | Name : FreeBSD Ports: mysql-server File : nvt/freebsd_mysql-server16.nasl |
2009-01-02 | Name : FreeBSD Ports: mysql-server File : nvt/freebsd_mysql-server15.nasl |
2008-11-19 | Name : Debian Security Advisory DSA 1662-1 (mysql-dfsg-5.0) File : nvt/deb_1662_1.nasl |
2008-09-25 | Name : MySQL Empty Bit-String Literal Denial of Service Vulnerability File : nvt/secpod_mysql_dos_vuln_900221.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200809-04 (mysql) File : nvt/glsa_200809_04.nasl |
2008-09-17 | Name : FreeBSD Ports: mysql-server File : nvt/freebsd_mysql-server14.nasl |
2008-07-15 | Name : Debian Security Advisory DSA 1608-1 (mysql-dfsg-5.0) File : nvt/deb_1608_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
54512 | PostgreSQL Client-specific Encoding Localized Error Message Conversion DoS |
54176 | DBD::Pg Module for Perl quote.c dequote_bytea Function Memory Consumption DoS |
54171 | DBD::Pg Module for Perl Multiple Function Overflow |
48021 | MySQL Empty Bit-String Literal Token SQL Statement DoS |
44937 | MySQL MyISAM Table CREATE TABLE Privilege Check Bypass |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2015-01-19 | Name : The remote Solaris system is missing a security patch for third-party software. File : solaris11_mysql_20130924.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2010-0110.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2010-0109.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2009-1484.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing a security update. File : oraclelinux_ELSA-2009-0479.nasl - Type : ACT_GATHER_INFO |
2013-01-24 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2009-1289.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20100216_mysql_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20100216_mysql_on_SL4_x.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20091007_postgresql_on_SL3_x.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20090902_mysql_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing a security update. File : sl_20090513_perl_DBD_Pg_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20080724_mysql_on_SL4_x.nasl - Type : ACT_GATHER_INFO |
2012-03-13 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-1397-1.nasl - Type : ACT_GATHER_INFO |
2012-01-16 | Name : The remote database server allows a local user to circumvent privileges. File : mysql_6_0_14_priv_bypass.nasl - Type : ACT_GATHER_INFO |
2012-01-06 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201201-02.nasl - Type : ACT_GATHER_INFO |
2011-10-25 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201110-22.nasl - Type : ACT_GATHER_INFO |
2010-07-30 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2010-012.nasl - Type : ACT_GATHER_INFO |
2010-03-02 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2010-0109.nasl - Type : ACT_GATHER_INFO |
2010-02-18 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2010-0110.nasl - Type : ACT_GATHER_INFO |
2010-02-17 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2010-0110.nasl - Type : ACT_GATHER_INFO |
2010-02-17 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2010-0109.nasl - Type : ACT_GATHER_INFO |
2010-02-11 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-897-1.nasl - Type : ACT_GATHER_INFO |
2010-01-18 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2010-011.nasl - Type : ACT_GATHER_INFO |
2010-01-06 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2009-1289.nasl - Type : ACT_GATHER_INFO |
2010-01-06 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2009-1484.nasl - Type : ACT_GATHER_INFO |
2010-01-06 | Name : The remote CentOS host is missing a security update. File : centos_RHSA-2009-0479.nasl - Type : ACT_GATHER_INFO |
2009-12-29 | Name : The remote Mandriva Linux host is missing a security update. File : mandriva_MDVSA-2009-344.nasl - Type : ACT_GATHER_INFO |
2009-12-08 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2009-326.nasl - Type : ACT_GATHER_INFO |
2009-11-25 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_1_41.nasl - Type : ACT_GATHER_INFO |
2009-10-08 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2009-1484.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 9 host is missing a security-related patch. File : suse9_12383.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_postgresql-6114.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_postgresql-090324.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 9 host is missing a security-related patch. File : suse9_12256.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 9 host is missing a security-related patch. File : suse9_12175.nasl - Type : ACT_GATHER_INFO |
2009-09-11 | Name : The remote host is missing a Mac OS X update that fixes various security issues. File : macosx_SecUpd2009-005.nasl - Type : ACT_GATHER_INFO |
2009-07-21 | Name : The remote openSUSE host is missing a security update. File : suse_11_0_libmysqlclient-devel-080919.nasl - Type : ACT_GATHER_INFO |
2009-07-21 | Name : The remote openSUSE host is missing a security update. File : suse_11_0_postgresql-090324.nasl - Type : ACT_GATHER_INFO |
2009-07-21 | Name : The remote openSUSE host is missing a security update. File : suse_11_1_postgresql-090324.nasl - Type : ACT_GATHER_INFO |
2009-06-28 | Name : The remote host is missing Sun Security Patch number 138827-12 File : solaris10_x86_138827.nasl - Type : ACT_GATHER_INFO |
2009-06-28 | Name : The remote host is missing Sun Security Patch number 138826-12 File : solaris10_138826.nasl - Type : ACT_GATHER_INFO |
2009-06-17 | Name : The remote openSUSE host is missing a security update. File : suse_perl-DBD-Pg-6227.nasl - Type : ACT_GATHER_INFO |
2009-05-14 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2009-0479.nasl - Type : ACT_GATHER_INFO |
2009-04-30 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1783.nasl - Type : ACT_GATHER_INFO |
2009-04-29 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1780.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2008-149.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-753-1.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-671-1.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Fedora host is missing a security update. File : fedora_2009-2959.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2008-150.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2009-094.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2009-079.nasl - Type : ACT_GATHER_INFO |
2009-04-16 | Name : The remote openSUSE host is missing a security update. File : suse_postgresql-6115.nasl - Type : ACT_GATHER_INFO |
2009-03-24 | Name : The remote Fedora host is missing a security update. File : fedora_2009-2927.nasl - Type : ACT_GATHER_INFO |
2009-01-12 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_66a770b4e00811dda7650030843d3802.nasl - Type : ACT_GATHER_INFO |
2008-12-30 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_738f8f9ed66111dda7650030843d3802.nasl - Type : ACT_GATHER_INFO |
2008-12-21 | Name : The remote openSUSE host is missing a security update. File : suse_libmysqlclient-devel-5619.nasl - Type : ACT_GATHER_INFO |
2008-12-01 | Name : The remote openSUSE host is missing a security update. File : suse_mysql-5613.nasl - Type : ACT_GATHER_INFO |
2008-11-13 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_mysql-5618.nasl - Type : ACT_GATHER_INFO |
2008-11-09 | Name : The remote database server is susceptible to a privilege bypass attack. File : mysql_es_5_0_70.nasl - Type : ACT_GATHER_INFO |
2008-11-06 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1662.nasl - Type : ACT_GATHER_INFO |
2008-10-10 | Name : The remote host is missing a Mac OS X update that fixes various security issues. File : macosx_SecUpd2008-007.nasl - Type : ACT_GATHER_INFO |
2008-09-11 | Name : The remote database server is affected by several issues. File : mysql_5_0_67.nasl - Type : ACT_GATHER_INFO |
2008-09-11 | Name : The remote database server is susceptible to a denial of service attack. File : mysql_5_1_26.nasl - Type : ACT_GATHER_INFO |
2008-09-11 | Name : The remote database server is susceptible to a denial of service attack. File : mysql_6_0_6.nasl - Type : ACT_GATHER_INFO |
2008-09-11 | Name : The remote database server is susceptible to a denial of service attack. File : mysql_es_5_0_66.nasl - Type : ACT_GATHER_INFO |
2008-09-10 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_388d9ee47f2211dda66a0019666436c2.nasl - Type : ACT_GATHER_INFO |
2008-09-05 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200809-04.nasl - Type : ACT_GATHER_INFO |
2008-08-14 | Name : The remote openSUSE host is missing a security update. File : suse_libmysqlclient-devel-5341.nasl - Type : ACT_GATHER_INFO |
2008-08-14 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_mysql-5338.nasl - Type : ACT_GATHER_INFO |
2008-07-25 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2008-0768.nasl - Type : ACT_GATHER_INFO |
2008-07-15 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1608.nasl - Type : ACT_GATHER_INFO |
2008-05-09 | Name : The remote database server allows a local user to circumvent privileges. File : mysql_4_1_24.nasl - Type : ACT_GATHER_INFO |
2008-05-09 | Name : The remote database server allows a local user to circumvent privileges. File : mysql_es_5_0_60.nasl - Type : ACT_GATHER_INFO |
2008-02-05 | Name : The remote host is missing Sun Security Patch number 136999-10 File : solaris10_x86_136999.nasl - Type : ACT_GATHER_INFO |
2008-02-05 | Name : The remote host is missing Sun Security Patch number 136998-10 File : solaris10_136998.nasl - Type : ACT_GATHER_INFO |
2007-03-18 | Name : The remote host is missing Sun Security Patch number 123591-12 File : solaris10_x86_123591.nasl - Type : ACT_GATHER_INFO |
2007-03-18 | Name : The remote host is missing Sun Security Patch number 123590-12 File : solaris10_123590.nasl - Type : ACT_GATHER_INFO |