Pike 使用Postgres数据库服务器不明SQL注入漏洞

漏洞信息详情

Pike 使用Postgres数据库服务器不明SQL注入漏洞

漏洞简介

Pike 7.6.86之前版本中存在SQL注入漏洞,在使用Postgres数据库服务器时,远程攻击者可借助不明攻击向量执行任意SQL指令。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Pike Pike 7.6.13

Ubuntu pike7.6-bzip2_7.6.13-1ubuntu0.1_amd64.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-bzip 2_7.6.13-1ubuntu0.1_amd64.deb

Ubuntu pike7.6-bzip2_7.6.13-1ubuntu0.1_i386.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-bzip 2_7.6.13-1ubuntu0.1_i386.deb

Ubuntu pike7.6-bzip2_7.6.13-1ubuntu0.1_powerpc.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-bzip 2_7.6.13-1ubuntu0.1_powerpc.deb

Ubuntu pike7.6-core_7.6.13-1ubuntu0.1_amd64.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-core_7.6 .13-1ubuntu0.1_amd64.deb

Ubuntu pike7.6-core_7.6.13-1ubuntu0.1_i386.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-core_7.6 .13-1ubuntu0.1_i386.deb

Ubuntu pike7.6-core_7.6.13-1ubuntu0.1_powerpc.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-core_7.6 .13-1ubuntu0.1_powerpc.deb

Ubuntu pike7.6-dev_7.6.13-1ubuntu0.1_all.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-dev_7.6. 13-1ubuntu0.1_all.deb

Ubuntu pike7.6-doc_7.6.13-1ubuntu0.1_all.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-doc_7.6. 13-1ubuntu0.1_all.deb

Ubuntu pike7.6-gdbm_7.6.13-1ubuntu0.1_amd64.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-gdbm_7.6 .13-1ubuntu0.1_amd64.deb

Ubuntu pike7.6-gdbm_7.6.13-1ubuntu0.1_i386.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-gdbm_7.6 .13-1ubuntu0.1_i386.deb

Ubuntu pike7.6-gdbm_7.6.13-1ubuntu0.1_powerpc.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-gdbm_7.6 .13-1ubuntu0.1_powerpc.deb

Ubuntu pike7.6-gl_7.6.13-1ubuntu0.1_amd64.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-gl_7 .6.13-1ubuntu0.1_amd64.deb

Ubuntu pike7.6-gl_7.6.13-1ubuntu0.1_i386.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-gl_7 .6.13-1ubuntu0.1_i386.deb

Ubuntu pike7.6-gl_7.6.13-1ubuntu0.1_powerpc.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-gl_7 .6.13-1ubuntu0.1_powerpc.deb

Ubuntu pike7.6-gtk_7.6.13-1ubuntu0.1_amd64.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-gtk_ 7.6.13-1ubuntu0.1_amd64.deb

Ubuntu pike7.6-gtk_7.6.13-1ubuntu0.1_i386.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-gtk_ 7.6.13-1ubuntu0.1_i386.deb

Ubuntu pike7.6-gtk_7.6.13-1ubuntu0.1_powerpc.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-gtk_ 7.6.13-1ubuntu0.1_powerpc.deb

Ubuntu pike7.6-image_7.6.13-1ubuntu0.1_amd64.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-image_7. 6.13-1ubuntu0.1_amd64.deb

Ubuntu pike7.6-image_7.6.13-1ubuntu0.1_i386.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-image_7. 6.13-1ubuntu0.1_i386.deb

Ubuntu pike7.6-image_7.6.13-1ubuntu0.1_powerpc.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-image_7. 6.13-1ubuntu0.1_powerpc.deb

Ubuntu pike7.6-manual_7.6.13-1ubuntu0.1_all.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-manual_7 .6.13-1ubuntu0.1_all.deb

Ubuntu pike7.6-meta_7.6.13-1ubuntu0.1_all.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-meta _7.6.13-1ubuntu0.1_all.deb

Ubuntu pike7.6-mysql_7.6.13-1ubuntu0.1_amd64.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-mysq l_7.6.13-1ubuntu0.1_amd64.deb

Ubuntu pike7.6-mysql_7.6.13-1ubuntu0.1_i386.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-mysq l_7.6.13-1ubuntu0.1_i386.deb

Ubuntu pike7.6-mysql_7.6.13-1ubuntu0.1_powerpc.deb

Ubuntu 5.04:

http://security.ubuntu.com/ubuntu/pool/universe/p/p

参考网址

来源: XF

名称: pike-sql-injection(26992)

链接:http://xforce.iss.net/xforce/xfdb/26992

来源: BID

名称: 19367

链接:http://www.securityfocus.com/bid/19367

来源: VUPEN

名称: ADV-2006-2209

链接:http://www.frsirt.com/english/advisories/2006/2209

来源: GENTOO

名称: GLSA-200608-10

链接:http://security.gentoo.org/glsa/glsa-200608-10.xml

来源: SECUNIA

名称: 21362

链接:http://secunia.com/advisories/21362

来源: SECUNIA

名称: 20494

链接:http://secunia.com/advisories/20494

来源: pike.ida.liu.se

链接:http://pike.ida.liu.se/download/notes/7.6.86.xml

来源: UBUNTU

名称: USN-367-1

链接:http://www.ubuntu.com/usn/usn-367-1

来源: SECUNIA

名称: 22481

链接:http://secunia.com/advisories/22481

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享