English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Sun Solaris PostgreSQL Privilege Escalation and Denial of Service


Secunia ID

SA37250

CVE-ID

CVE-2009-3229, CVE-2009-3230

Release Date

04 Nov 2009

Criticality

Less Critical

Solution Status

Vendor Patch

Where

From local network

Impact
DoS (Denial of Service)

This includes vulnerabilities ranging from excessive resource consumption (e.g. causing a system to use a lot of memory) to crashing an application or an entire system.

Privilege escalation

This covers vulnerabilities where a user is able to conduct certain tasks with the privileges of other users or administrative users.

This typically includes cases where a local user on a client or server system can gain access to the administrator or root account thus taking full control of the system.

Description

Sun has acknowledged some vulnerabilities in PostgreSQL in Solaris, which can be exploited by malicious users to gain escalated privileges and cause a DoS (Denial of Service).

For more information:
SA36660

The vulnerabilities are reported in Solaris 10 and OpenSolaris on both the SPARC and x86 platforms.

Solution

Apply patches.

-- SPARC Platform --

Solaris 10 (6/06 or later) with PostgreSQL 8.1:
Apply patch 123590-11 or later.

Solaris 10 (8/07 or later) with PostgreSQL 8.2:
Apply patch 136998-07 or later.

Solaris 10 (10/08 or later) with PostgreSQL 8.3:
Apply patch 138826-05 or later.

OpenSolaris with PostgreSQL 8.2/8.3:
Fixed in builds snv_125 and later.

-- x86 Platform --

Solaris 10 (6/06 or later) with PostgreSQL 8.1:
Apply patch 123591-11 or later.

Solaris 10 (8/07 or later) with PostgreSQL 8.2:
Apply patch 136999-07 or later.

Solaris 10 (10/08 or later) with PostgreSQL 8.3:
Apply patch 138827-05 or later.

OpenSolaris with PostgreSQL 8.2/8.3:
Fixed in builds snv_125 and later.

Original Advisory

http://sunsolve.sun.com/search/document.do?assetkey=1-66-270408-1