FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-2314

This CVE name corresponds to:

Entered Topic
2006-08-13 postgresql -- encoding based SQL injection

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-2314
Phase Assigned(20060511)

Description

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.

References

Source Reference
BUGTRAQ 20060523 PostgreSQL security releases 8.1.4, 8.0.8, 7.4.13, 7.3.15
BUGTRAQ 20060524 rPSA-2006-0080-1 postgresql postgresql-server
MLIST [pgsql-announce] 20060523 Security Releases for All Active Versions
CONFIRM http://www.postgresql.org/docs/techdocs.50
CONFIRM http://support.avaya.com/elmodocs2/security/ASA-2006-113.htm
DEBIAN DSA-1087
GENTOO GLSA-200607-04
MANDRIVA MDKSA-2006:098
REDHAT RHSA-2006:0526
SGI 20060602-01-U
SUSE SUSE-SA:2006:030
SUSE SUSE-SR:2006:021
TRUSTIX 2006-0032
UBUNTU USN-288-1
UBUNTU USN-288-2
UBUNTU USN-288-3
BID 18092
OVAL oval:org.mitre.oval:def:9947
VUPEN ADV-2006-1941
OSVDB 25731
SECTRACK 1016142
SECUNIA 20231
SECUNIA 20232
SECUNIA 20314
SECUNIA 20435
SECUNIA 20451
SECUNIA 20503
SECUNIA 20555
SECUNIA 20782
SECUNIA 21001
SECUNIA 21749
SECUNIA 20653
XF postgresql-ascii-sql-injection(26628)
XF postgresql-multibyte-sql-injection(26627)