Rapid7 Vulnerability & Exploit Database

RHSA-2007:0064: postgresql security update

Back to Search

RHSA-2007:0064: postgresql security update



Updated postgresql packages that fix two security issues are now available for Red Hat Enterprise Linux 3 and 4. This update has been rated as having moderate security impact by the Red Hat Security Response Team.

PostgreSQL is an advanced Object-Relational database management system (DBMS). A flaw was found in the way the PostgreSQL server handles certain SQL-language functions. An authenticated user could execute a sequence of commands which could crash the PostgreSQL server or possibly read from arbitrary memory locations. A user would need to have permissions to drop and add database tables to be able to exploit this issue (CVE-2007-0555). A denial of service flaw was found affecting the PostgreSQL server running on Red Hat Enterprise Linux 4 systems. An authenticated user could execute an SQL command which could crash the PostgreSQL server. (CVE-2006-5540) Users of PostgreSQL should upgrade to these updated packages containing PostgreSQL version 7.4.16 or 7.3.18, which correct these issues.


  • redhat-upgrade-postgresql
  • redhat-upgrade-postgresql-contrib
  • redhat-upgrade-postgresql-devel
  • redhat-upgrade-postgresql-docs
  • redhat-upgrade-postgresql-jdbc
  • redhat-upgrade-postgresql-libs
  • redhat-upgrade-postgresql-pl
  • redhat-upgrade-postgresql-python
  • redhat-upgrade-postgresql-server
  • redhat-upgrade-postgresql-tcl
  • redhat-upgrade-postgresql-test
  • redhat-upgrade-rh-postgresql
  • redhat-upgrade-rh-postgresql-contrib
  • redhat-upgrade-rh-postgresql-devel
  • redhat-upgrade-rh-postgresql-docs
  • redhat-upgrade-rh-postgresql-jdbc
  • redhat-upgrade-rh-postgresql-libs
  • redhat-upgrade-rh-postgresql-pl
  • redhat-upgrade-rh-postgresql-python
  • redhat-upgrade-rh-postgresql-server
  • redhat-upgrade-rh-postgresql-tcl
  • redhat-upgrade-rh-postgresql-test

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center