漏洞信息详情
Pike 使用Postgres数据库服务器不明SQL注入漏洞
- CNNVD编号:CNNVD-200608-169
- 危害等级: 高危
- CVE编号:
CVE-2006-4041
- 漏洞类型:
SQL注入
- 发布时间:
2006-08-09
- 威胁类型:
远程
- 更新时间:
2006-08-14
- 厂 商:
pike - 漏洞来源:
Pike -
漏洞简介
Pike 7.6.86之前版本中存在SQL注入漏洞,在使用Postgres数据库服务器时,远程攻击者可借助不明攻击向量执行任意SQL指令。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Pike Pike 7.6.13
Ubuntu pike7.6-bzip2_7.6.13-1ubuntu0.1_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-bzip 2_7.6.13-1ubuntu0.1_amd64.deb
Ubuntu pike7.6-bzip2_7.6.13-1ubuntu0.1_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-bzip 2_7.6.13-1ubuntu0.1_i386.deb
Ubuntu pike7.6-bzip2_7.6.13-1ubuntu0.1_powerpc.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-bzip 2_7.6.13-1ubuntu0.1_powerpc.deb
Ubuntu pike7.6-core_7.6.13-1ubuntu0.1_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-core_7.6 .13-1ubuntu0.1_amd64.deb
Ubuntu pike7.6-core_7.6.13-1ubuntu0.1_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-core_7.6 .13-1ubuntu0.1_i386.deb
Ubuntu pike7.6-core_7.6.13-1ubuntu0.1_powerpc.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-core_7.6 .13-1ubuntu0.1_powerpc.deb
Ubuntu pike7.6-dev_7.6.13-1ubuntu0.1_all.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-dev_7.6. 13-1ubuntu0.1_all.deb
Ubuntu pike7.6-doc_7.6.13-1ubuntu0.1_all.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-doc_7.6. 13-1ubuntu0.1_all.deb
Ubuntu pike7.6-gdbm_7.6.13-1ubuntu0.1_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-gdbm_7.6 .13-1ubuntu0.1_amd64.deb
Ubuntu pike7.6-gdbm_7.6.13-1ubuntu0.1_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-gdbm_7.6 .13-1ubuntu0.1_i386.deb
Ubuntu pike7.6-gdbm_7.6.13-1ubuntu0.1_powerpc.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-gdbm_7.6 .13-1ubuntu0.1_powerpc.deb
Ubuntu pike7.6-gl_7.6.13-1ubuntu0.1_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-gl_7 .6.13-1ubuntu0.1_amd64.deb
Ubuntu pike7.6-gl_7.6.13-1ubuntu0.1_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-gl_7 .6.13-1ubuntu0.1_i386.deb
Ubuntu pike7.6-gl_7.6.13-1ubuntu0.1_powerpc.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-gl_7 .6.13-1ubuntu0.1_powerpc.deb
Ubuntu pike7.6-gtk_7.6.13-1ubuntu0.1_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-gtk_ 7.6.13-1ubuntu0.1_amd64.deb
Ubuntu pike7.6-gtk_7.6.13-1ubuntu0.1_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-gtk_ 7.6.13-1ubuntu0.1_i386.deb
Ubuntu pike7.6-gtk_7.6.13-1ubuntu0.1_powerpc.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-gtk_ 7.6.13-1ubuntu0.1_powerpc.deb
Ubuntu pike7.6-image_7.6.13-1ubuntu0.1_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-image_7. 6.13-1ubuntu0.1_amd64.deb
Ubuntu pike7.6-image_7.6.13-1ubuntu0.1_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-image_7. 6.13-1ubuntu0.1_i386.deb
Ubuntu pike7.6-image_7.6.13-1ubuntu0.1_powerpc.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-image_7. 6.13-1ubuntu0.1_powerpc.deb
Ubuntu pike7.6-manual_7.6.13-1ubuntu0.1_all.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/main/p/pike7.6/pike7.6-manual_7 .6.13-1ubuntu0.1_all.deb
Ubuntu pike7.6-meta_7.6.13-1ubuntu0.1_all.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-meta _7.6.13-1ubuntu0.1_all.deb
Ubuntu pike7.6-mysql_7.6.13-1ubuntu0.1_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-mysq l_7.6.13-1ubuntu0.1_amd64.deb
Ubuntu pike7.6-mysql_7.6.13-1ubuntu0.1_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/p/pike7.6/pike7.6-mysq l_7.6.13-1ubuntu0.1_i386.deb
Ubuntu pike7.6-mysql_7.6.13-1ubuntu0.1_powerpc.deb
Ubuntu 5.04:
参考网址
来源: XF
名称: pike-sql-injection(26992)
链接:http://xforce.iss.net/xforce/xfdb/26992
来源: BID
名称: 19367
链接:http://www.securityfocus.com/bid/19367
来源: VUPEN
名称: ADV-2006-2209
链接:http://www.frsirt.com/english/advisories/2006/2209
来源: GENTOO
名称: GLSA-200608-10
链接:http://security.gentoo.org/glsa/glsa-200608-10.xml
来源: SECUNIA
名称: 21362
链接:http://secunia.com/advisories/21362
来源: SECUNIA
名称: 20494
链接:http://secunia.com/advisories/20494
来源: pike.ida.liu.se
链接:http://pike.ida.liu.se/download/notes/7.6.86.xml
来源: UBUNTU
名称: USN-367-1
链接:http://www.ubuntu.com/usn/usn-367-1
来源: SECUNIA
名称: 22481