Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2006-2314
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-2314

Description:
PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/26628
  http://xforce.iss.net/xforce/xfdb/26627

UBUNTU
  http://www.ubuntu.com/usn/usn-288-3
  http://www.ubuntu.com/usn/usn-288-2
  http://www.ubuntulinux.org/support/documentation/usn/usn-288-1

TRUSTIX
  http://www.trustix.org/errata/2006/0032/

SUSE
  http://www.novell.com/linux/security/advisories/2006_21_sr.html
  http://lists.suse.com/archive/suse-security-announce/2006-Jun/0002.html

ST
  1016142

SGI

SAID
  Secunia Advisory: SA20451
  Secunia Advisory: SA20503
  Secunia Advisory: SA20314
  Secunia Advisory: SA20435
  Secunia Advisory: SA20231
  Secunia Advisory: SA20232
  Secunia Advisory: SA20555
  Secunia Advisory: SA20782
  Secunia Advisory: SA21001
  Secunia Advisory: SA21749
  Secunia Advisory: SA20653

REDHAT
  http://www.redhat.com/support/errata/RHSA-2006-0526.html

OSVDB
  25731

MLIST
  http://archives.postgresql.org/pgsql-announce/2006-05/msg00010.php

MANDRIVA
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:098

GENTOO
  http://security.gentoo.org/glsa/glsa-200607-04.xml

DEBIAN
  http://www.debian.org/security/2006/dsa-1087

CONFIRM
  http://support.avaya.com/elmodocs2/security/ASA-2006-113.htm
  http://www.postgresql.org/docs/techdocs.50

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/435161/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/435038/100/0/threaded

BID
  18092


Return to the previous page.