VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-1170
postgresql: The PL/Tcl implementation in PostgreSQL 7.4 before ...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1170

Original

The PL/Tcl implementation in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2 loads Tcl code from the pltcl_modules table regardless of the table's ownership and permissions, which allows remote authenticated users, with database-creation privileges, to execute arbitrary Tcl code by creating this table and inserting a crafted Tcl script.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-05-19
Source Information Category:
Advisory, Alert
Last Updated:
2010-05-20




Affected Product Tags
cpe:/a:postgresql:postgresql:7.4
cpe:/a:postgresql:postgresql:7.4.1
cpe:/a:postgresql:postgresql:7.4.10
cpe:/a:postgresql:postgresql:7.4.11
cpe:/a:postgresql:postgresql:7.4.12
cpe:/a:postgresql:postgresql:7.4.13
cpe:/a:postgresql:postgresql:7.4.14
cpe:/a:postgresql:postgresql:7.4.15
cpe:/a:postgresql:postgresql:7.4.16
cpe:/a:postgresql:postgresql:7.4.17
cpe:/a:postgresql:postgresql:7.4.18
cpe:/a:postgresql:postgresql:7.4.19
cpe:/a:postgresql:postgresql:7.4.2
cpe:/a:postgresql:postgresql:7.4.20
cpe:/a:postgresql:postgresql:7.4.21
cpe:/a:postgresql:postgresql:7.4.22
cpe:/a:postgresql:postgresql:7.4.23
cpe:/a:postgresql:postgresql:7.4.24
cpe:/a:postgresql:postgresql:7.4.25
cpe:/a:postgresql:postgresql:7.4.26
cpe:/a:postgresql:postgresql:7.4.27
cpe:/a:postgresql:postgresql:7.4.28
cpe:/a:postgresql:postgresql:7.4.3
cpe:/a:postgresql:postgresql:7.4.4
cpe:/a:postgresql:postgresql:7.4.5
cpe:/a:postgresql:postgresql:7.4.6
cpe:/a:postgresql:postgresql:7.4.7
cpe:/a:postgresql:postgresql:7.4.8
cpe:/a:postgresql:postgresql:7.4.9
cpe:/a:postgresql:postgresql:8.0
cpe:/a:postgresql:postgresql:8.0.0
cpe:/a:postgresql:postgresql:8.0.1
cpe:/a:postgresql:postgresql:8.0.10
cpe:/a:postgresql:postgresql:8.0.11
cpe:/a:postgresql:postgresql:8.0.12
cpe:/a:postgresql:postgresql:8.0.13
cpe:/a:postgresql:postgresql:8.0.14
cpe:/a:postgresql:postgresql:8.0.15
cpe:/a:postgresql:postgresql:8.0.16
cpe:/a:postgresql:postgresql:8.0.17
cpe:/a:postgresql:postgresql:8.0.18
cpe:/a:postgresql:postgresql:8.0.19
cpe:/a:postgresql:postgresql:8.0.2
cpe:/a:postgresql:postgresql:8.0.20
cpe:/a:postgresql:postgresql:8.0.21
cpe:/a:postgresql:postgresql:8.0.22
cpe:/a:postgresql:postgresql:8.0.23
cpe:/a:postgresql:postgresql:8.0.24
cpe:/a:postgresql:postgresql:8.0.3
cpe:/a:postgresql:postgresql:8.0.4
cpe:/a:postgresql:postgresql:8.0.5
cpe:/a:postgresql:postgresql:8.0.6
cpe:/a:postgresql:postgresql:8.0.7
cpe:/a:postgresql:postgresql:8.0.8
cpe:/a:postgresql:postgresql:8.0.9
cpe:/a:postgresql:postgresql:8.1
cpe:/a:postgresql:postgresql:8.1.0
cpe:/a:postgresql:postgresql:8.1.1
cpe:/a:postgresql:postgresql:8.1.10
cpe:/a:postgresql:postgresql:8.1.11
cpe:/a:postgresql:postgresql:8.1.12
cpe:/a:postgresql:postgresql:8.1.13
cpe:/a:postgresql:postgresql:8.1.14
cpe:/a:postgresql:postgresql:8.1.15
cpe:/a:postgresql:postgresql:8.1.16
cpe:/a:postgresql:postgresql:8.1.17
cpe:/a:postgresql:postgresql:8.1.18
cpe:/a:postgresql:postgresql:8.1.19
cpe:/a:postgresql:postgresql:8.1.2
cpe:/a:postgresql:postgresql:8.1.20
cpe:/a:postgresql:postgresql:8.1.3
cpe:/a:postgresql:postgresql:8.1.4
cpe:/a:postgresql:postgresql:8.1.5
cpe:/a:postgresql:postgresql:8.1.6
cpe:/a:postgresql:postgresql:8.1.7
cpe:/a:postgresql:postgresql:8.1.8
cpe:/a:postgresql:postgresql:8.1.9
cpe:/a:postgresql:postgresql:8.2
cpe:/a:postgresql:postgresql:8.2.1
cpe:/a:postgresql:postgresql:8.2.10
cpe:/a:postgresql:postgresql:8.2.11
cpe:/a:postgresql:postgresql:8.2.12
cpe:/a:postgresql:postgresql:8.2.13
cpe:/a:postgresql:postgresql:8.2.14
cpe:/a:postgresql:postgresql:8.2.15
cpe:/a:postgresql:postgresql:8.2.16
cpe:/a:postgresql:postgresql:8.2.2
cpe:/a:postgresql:postgresql:8.2.3
cpe:/a:postgresql:postgresql:8.2.4
cpe:/a:postgresql:postgresql:8.2.5
cpe:/a:postgresql:postgresql:8.2.6
cpe:/a:postgresql:postgresql:8.2.7
cpe:/a:postgresql:postgresql:8.2.8
cpe:/a:postgresql:postgresql:8.2.9
cpe:/a:postgresql:postgresql:8.3
cpe:/a:postgresql:postgresql:8.3.1
cpe:/a:postgresql:postgresql:8.3.10
cpe:/a:postgresql:postgresql:8.3.2
cpe:/a:postgresql:postgresql:8.3.3
cpe:/a:postgresql:postgresql:8.3.4
cpe:/a:postgresql:postgresql:8.3.5
cpe:/a:postgresql:postgresql:8.3.6
cpe:/a:postgresql:postgresql:8.3.7
cpe:/a:postgresql:postgresql:8.3.8
cpe:/a:postgresql:postgresql:8.3.9
cpe:/a:postgresql:postgresql:8.4
cpe:/a:postgresql:postgresql:8.4.1
cpe:/a:postgresql:postgresql:8.4.2
cpe:/a:postgresql:postgresql:8.4.3
cpe:/a:postgresql:postgresql:9.0.0:beta1
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
X Single [?]
None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

Alternatives




References
BID 40215




CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=583072




CONFIRM http://www.postgresql.org/support/security




CONFIRM http://www.postgresql.org/docs/current/static/release-8-4-4.html




CONFIRM http://www.postgresql.org/docs/current/static/release-8-3-11.html




CONFIRM http://www.postgresql.org/docs/current/static/release-8-2-17.html




CONFIRM http://www.postgresql.org/docs/current/static/release-8-1-21.html




CONFIRM http://www.postgresql.org/docs/current/static/release-8-0-25.html




CONFIRM http://www.postgresql.org/docs/current/static/release-7-4-29.html




CONFIRM http://www.postgresql.org/about/news.1203




SECUNIA 39845




VUPEN ADV-2010-1167




Vulnerability Type Permissions, Privileges, and Access Control (CWE-264)





Copyright © 2010 JPCERT/CC All Rights Reserved.