CVE-2007-0556

N/A Unknown
Published: February 06, 2007 Modified: April 23, 2026
View on NVD

Description

The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a "previously made query plan," which allows remote authenticated users to cause a denial of service (server crash) and possibly access database content via an "ALTER COLUMN TYPE" SQL statement, which can be leveraged to read arbitrary memory from the server.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/33302
Source: cve@mitre.org
http://secunia.com/advisories/24033
Source: cve@mitre.org
Vendor Advisory
https://usn.ubuntu.com/417-1/
Source: cve@mitre.org
http://fedoranews.org/cms/node/2554
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/33302
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/24028
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/24033
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/24042
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/24050
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/24057
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/24151
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/24315
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/24513
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/24577
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25220
Source: af854a3a-2127-422b-91ae-364da2661108
http://security.gentoo.org/glsa/glsa-200703-15.xml
Source: af854a3a-2127-422b-91ae-364da2661108
http://securitytracker.com/id?1017597
Source: af854a3a-2127-422b-91ae-364da2661108
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102825-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://support.avaya.com/elmodocs2/security/ASA-2007-117.htm
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDKSA-2007:037
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.novell.com/linux/security/advisories/2007_10_sr.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.postgresql.org/support/security
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2007-0067.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2007-0068.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/459280/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/459448/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/22387
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.trustix.org/errata/2007/0007
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-417-2
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/0478
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/0774
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/32191
Source: af854a3a-2127-422b-91ae-364da2661108
https://issues.rpath.com/browse/RPL-1025
Source: af854a3a-2127-422b-91ae-364da2661108
https://issues.rpath.com/browse/RPL-830
Source: af854a3a-2127-422b-91ae-364da2661108
https://usn.ubuntu.com/417-1/
Source: af854a3a-2127-422b-91ae-364da2661108

68 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
1.9%
83th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

postgresql