CVE-2007-0556
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/02/2007
Last modified:
09/04/2025
Description
The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a "previously made query plan," which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content via an "ALTER COLUMN TYPE" SQL statement, which can be leveraged to read arbitrary memory from the server.
Impact
Base Score 2.0
6.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:postgresql:postgresql:1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:1.01:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:1.02:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:1.09:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:6.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:6.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:6.1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:6.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:6.2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:6.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:6.3.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:6.3.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:6.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:6.4.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:postgresql:postgresql:6.4.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://fedoranews.org/cms/node/2554
- http://lists.rpath.com/pipermail/security-announce/2007-February/000141.html
- http://osvdb.org/33302
- http://secunia.com/advisories/24028
- http://secunia.com/advisories/24033
- http://secunia.com/advisories/24042
- http://secunia.com/advisories/24050
- http://secunia.com/advisories/24057
- http://secunia.com/advisories/24151
- http://secunia.com/advisories/24315
- http://secunia.com/advisories/24513
- http://secunia.com/advisories/24577
- http://secunia.com/advisories/25220
- http://security.gentoo.org/glsa/glsa-200703-15.xml
- http://securitytracker.com/id?1017597=
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102825-1
- http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm
- http://www.mandriva.com/security/advisories?name=MDKSA-2007%3A037
- http://www.novell.com/linux/security/advisories/2007_10_sr.html
- http://www.postgresql.org/support/security
- http://www.redhat.com/support/errata/RHSA-2007-0067.html
- http://www.redhat.com/support/errata/RHSA-2007-0068.html
- http://www.securityfocus.com/archive/1/459280/100/0/threaded
- http://www.securityfocus.com/archive/1/459448/100/0/threaded
- http://www.securityfocus.com/bid/22387
- http://www.trustix.org/errata/2007/0007
- http://www.ubuntu.com/usn/usn-417-2
- http://www.vupen.com/english/advisories/2007/0478
- http://www.vupen.com/english/advisories/2007/0774
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32191
- https://issues.rpath.com/browse/RPL-1025
- https://issues.rpath.com/browse/RPL-830
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11353
- https://usn.ubuntu.com/417-1/
- http://fedoranews.org/cms/node/2554
- http://lists.rpath.com/pipermail/security-announce/2007-February/000141.html
- http://osvdb.org/33302
- http://secunia.com/advisories/24028
- http://secunia.com/advisories/24033
- http://secunia.com/advisories/24042
- http://secunia.com/advisories/24050
- http://secunia.com/advisories/24057
- http://secunia.com/advisories/24151
- http://secunia.com/advisories/24315
- http://secunia.com/advisories/24513
- http://secunia.com/advisories/24577
- http://secunia.com/advisories/25220
- http://security.gentoo.org/glsa/glsa-200703-15.xml
- http://securitytracker.com/id?1017597=
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102825-1
- http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm
- http://www.mandriva.com/security/advisories?name=MDKSA-2007%3A037
- http://www.novell.com/linux/security/advisories/2007_10_sr.html
- http://www.postgresql.org/support/security
- http://www.redhat.com/support/errata/RHSA-2007-0067.html
- http://www.redhat.com/support/errata/RHSA-2007-0068.html
- http://www.securityfocus.com/archive/1/459280/100/0/threaded
- http://www.securityfocus.com/archive/1/459448/100/0/threaded
- http://www.securityfocus.com/bid/22387
- http://www.trustix.org/errata/2007/0007
- http://www.ubuntu.com/usn/usn-417-2
- http://www.vupen.com/english/advisories/2007/0478
- http://www.vupen.com/english/advisories/2007/0774
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32191
- https://issues.rpath.com/browse/RPL-1025
- https://issues.rpath.com/browse/RPL-830
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11353
- https://usn.ubuntu.com/417-1/



