bk99.de entertain the web since 1997

Critical security holes in PostgreSQL closed

Summary

In January 2008 the PostgreSQL developers closed five critical holes in all maintained versions from 7.3 to 8.2. Via expression indexes and DBLink functions, attackers could gain administrator rights, and via regular expressions they could bring the server down with a denial of service. The holes were found in the project’s own analyses, and no exploits were known.

Ideas

  • Functions in indexes ran with the wrong privileges.
  • Regular expressions with prepared patterns can overload servers.
  • Extensions such as DBLink enlarge a database’s attack surface.
  • Fixes came for all still maintained versions at the same time.

Insights

  • Privilege checks in databases must also cover indirect execution paths.
  • Proactive analyses and broad version maintenance are strengths of mature open source projects.

Facts

  • The privilege escalation via expression indexes is listed as CVE-2007-6600.
  • The DBLink hole has the identifier CVE-2007-6601.
  • The fixes appeared as 8.2.6, 8.1.11, 8.0.15, 7.4.19 and 7.3.21; 7.3.21 was the last update for 7.3.

References

Critique

  • The report names the identifiers but does not explain what user rights an attacker needed at minimum.

Recommendations

  • Only install the database extensions that are actually needed.
  • Do not give application accounts the right to create functions or indexes unless necessary.

Read the original article

Search the Web Archive