Vulnerabilities > CVE-2007-4639 - Access of Uninitialized Pointer vulnerability in Enterprisedb Postgres Advanced Server 8.2

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
enterprisedb
CWE-824
exploit available

Summary

EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listener, which allows remote authenticated users to cause a denial of service (daemon crash) and possibly execute arbitrary code via a SELECT statement that invokes a pldbg_ function, as demonstrated by (1) pldbg_get_stack and (2) pldbg_abort_target, which triggers use of an uninitialized pointer.

Vulnerable Configurations

Part Description Count
Application
Enterprisedb
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionEnterpriseDB Advanced Server 8.2 Uninitialized Pointer Vulnerability. CVE-2007-4639. Dos exploit for linux platform
idEDB-ID:30542
last seen2016-02-03
modified2007-08-29
published2007-08-29
reporterJoxean Koret
sourcehttps://www.exploit-db.com/download/30542/
titleEnterpriseDB Advanced Server 8.2 Uninitialized Pointer Vulnerability

Redhat

rpmsEnterpriseDB-0:8.1.9.27-1