Submitted by KeesCook on Wed, 2006-10-18 12:06
Referenced CVEs:
CVE-2006-4041
Description:
===========================================================
Ubuntu Security Notice USN-367-1 October 18, 2006
pike7.6 vulnerability
CVE-2006-4041
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 5.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 5.04:
pike7.6-pg 7.6.13-1ubuntu0.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
An SQL injection was discovered in Pike's PostgreSQL module.
Applications using a PostgreSQL database and uncommon character
encodings could be fooled into running arbitrary SQL commands, which
could result in privilege escalation within the application, application
data exposure, or denial of service.
Please refer to http://www.ubuntu.com/usn/usn-288-1 for more detailled
information.


