CVE-2007-0556

Publication date 6 February 2007

Last updated 24 July 2024


Ubuntu priority

The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a "previously made query plan," which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content via an "ALTER COLUMN TYPE" SQL statement, which can be leveraged to read arbitrary memory from the server.

Status

Package Ubuntu Release Status
postgresql-8.1 7.04 feisty
Fixed 8.1.8-1ubuntu3
6.10 edgy
Fixed 8.1.9-0ubuntu0.6.10
6.06 LTS dapper
Fixed 8.1.9-0ubuntu0.6.06
postgresql-8.2 7.04 feisty
Fixed 8.2.4-0ubuntu0.7.04
6.10 edgy Not in release
6.06 LTS dapper Not in release

References

Related Ubuntu Security Notices (USN)

    • USN-417-1
    • PostgreSQL vulnerabilities
    • 6 February 2007

Other references