The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, and 8.2 before 8.2.14 allows remote authenticated users to cause a denial of service (backend shutdown) by “re-LOAD-ing” libraries from a certain plugins directory.
CPE | Name | Operator | Version |
---|---|---|---|
postgresql | eq | 8.2.9 | |
postgresql | eq | 8.3.6 | |
postgresql | eq | 8.2.10 | |
postgresql | eq | 8.2.4 | |
postgresql | eq | 8.2.11 | |
postgresql | eq | 8.2.12 | |
postgresql | eq | 8.2.2 | |
postgresql | eq | 8.3.3 | |
postgresql | eq | 8.3.2 | |
postgresql | eq | 8.2.5 |
lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html
lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html
secunia.com/advisories/36660
secunia.com/advisories/36727
secunia.com/advisories/36800
secunia.com/advisories/36837
sunsolve.sun.com/search/document.do?assetkey=1-66-270408-1
wiki.rpath.com/wiki/Advisories:rPSA-2010-0012
www.postgresql.org/docs/8.3/static/release-8-3-8.html
www.postgresql.org/support/security.html
www.securityfocus.com/archive/1/509917/100/0/threaded
www.securityfocus.com/bid/36314
www.ubuntu.com/usn/usn-834-1
www.us.debian.org/security/2009/dsa-1900
bugzilla.redhat.com/show_bug.cgi?id=522092
marc.info/?l=bugtraq&m=134124585221119&w=2
www.redhat.com/archives/fedora-package-announce/2009-September/msg00305.html
www.redhat.com/archives/fedora-package-announce/2009-September/msg00307.html