漏洞描述
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a denial of service (file corruption), and allows remote authenticated users to modify configuration settings and execute arbitrary code, via a connection request using a database name that begins with a "-" (hyphen).
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
support.apple.comhttp://support.apple.com/kb/HT5880↗lists.fedoraproject.orghttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/102806.html↗lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00008.html↗www.debian.orghttp://www.debian.org/security/2013/dsa-2658↗www.postgresql.orghttp://www.postgresql.org/support/security/faq/2013-04-04/↗lists.fedoraproject.orghttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/101519.html↗lists.apple.comhttp://lists.apple.com/archives/security-announce/2013/Sep/msg00004.html↗www.postgresql.orghttp://www.postgresql.org/docs/current/static/release-9-0-13.html↗support.apple.comhttp://support.apple.com/kb/HT5892↗www.mandriva.comhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:142↗www.postgresql.orghttp://www.postgresql.org/docs/current/static/release-9-1-9.html↗lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00011.html↗www.postgresql.orghttp://www.postgresql.org/docs/current/static/release-9-2-4.html↗lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00007.html↗www.ubuntu.comhttp://www.ubuntu.com/usn/USN-1789-1↗lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00012.html↗www.postgresql.orghttp://www.postgresql.org/about/news/1456/↗lists.apple.comhttp://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html↗