Critical security holes in PostgreSQL closed
Summary
In January 2008 the PostgreSQL developers closed five critical holes in all maintained versions from 7.3 to 8.2. Via expression indexes and DBLink functions, attackers could gain administrator rights, and via regular expressions they could bring the server down with a denial of service. The holes were found in the project’s own analyses, and no exploits were known.
Ideas
- Functions in indexes ran with the wrong privileges.
- Regular expressions with prepared patterns can overload servers.
- Extensions such as DBLink enlarge a database’s attack surface.
- Fixes came for all still maintained versions at the same time.
Insights
- Privilege checks in databases must also cover indirect execution paths.
- Proactive analyses and broad version maintenance are strengths of mature open source projects.
Facts
- The privilege escalation via expression indexes is listed as CVE-2007-6600.
- The DBLink hole has the identifier CVE-2007-6601.
- The fixes appeared as 8.2.6, 8.1.11, 8.0.15, 7.4.19 and 7.3.21; 7.3.21 was the last update for 7.3.
References
Critique
- The report names the identifiers but does not explain what user rights an attacker needed at minimum.
Recommendations
- Only install the database extensions that are actually needed.
- Do not give application accounts the right to create functions or indexes unless necessary.
Links to the original source and the Web Archive open in a new tab.