<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Hero &#187; Postgresql</title>
	<atom:link href="http://sechero.com/tag/postgresql/feed/" rel="self" type="application/rss+xml" />
	<link>http://sechero.com</link>
	<description>If it's about security, you heard it here first</description>
	<lastBuildDate>Mon, 12 Jul 2010 23:27:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>[SECURITY] [DSA 1909-1] New postgresql-ocaml packages provide secure escaping</title>
		<link>http://sechero.com/security-dsa-1909-1-new-postgresql-ocaml-packages-provide-secure-escaping/</link>
		<comments>http://sechero.com/security-dsa-1909-1-new-postgresql-ocaml-packages-provide-secure-escaping/#comments</comments>
		<pubDate>Thu, 15 Oct 2009 23:46:36 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Bugtraq]]></category>
		<category><![CDATA[Postgresql]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://sechero.com/?p=20967</guid>
		<description><![CDATA[Bugtraq: [SECURITY] [DSA 1909-1] New postgresql-ocaml packages provide secure escaping [SECURITY] [DSA 1909-1] New postgresql-ocaml packages provide secure escaping URL: http://www.securityfocus.com/archive/1/507190]]></description>
			<content:encoded><![CDATA[<h1><a href="http://www.securityfocus.com/archive/1/507190">Bugtraq: [SECURITY] [DSA 1909-1] New postgresql-ocaml packages provide secure escaping</a></h1>
<p>[SECURITY] [DSA 1909-1] New postgresql-ocaml packages provide secure escaping
<p>URL: <a href="http://www.securityfocus.com/archive/1/507190">http://www.securityfocus.com/archive/1/507190</a></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/security-dsa-1909-1-new-postgresql-ocaml-packages-provide-secure-escaping/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PostgreSQL vulnerability</title>
		<link>http://sechero.com/postgresql-vulnerability-2/</link>
		<comments>http://sechero.com/postgresql-vulnerability-2/#comments</comments>
		<pubDate>Tue, 07 Apr 2009 17:40:01 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Bugtraq]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[Postgresql]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://sechero.com/postgresql-vulnerability-2/</guid>
		<description><![CDATA[[USN-753-1] PostgreSQL vulnerability &#60;!&#8211; Envelope-to: email@address Delivery-date: Tue, 07 Apr 2009 18:36:12 +0100 Received: from outgoing.securityfocus.com ([205.206.231.27] helo=outgoing3.securityfocus.com) by lt.network5.net with esmtp (Exim 4.43) id 1LrFDX-00055K-TP for email@address; Tue, 07 Apr 2009 18:36:12 +0100 Received: from lists2.securityfocus.com (lists2.securityfocus.com [205.206.231.20]) by outgoing3.securityfocus.com (Postfix) with QMQP id DE1F223736A; Tue, 7 Apr 2009 10:33:59 -0600 (MDT) Mailing-List: contact [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://lists.rootsecure.net/?p=view&amp;l=bugtraq&amp;m=84816">[USN-753-1] PostgreSQL vulnerability</a></h1>
</p>
<p>&lt;!&#8211; Envelope-to: email@address Delivery-date: Tue, 07 Apr 2009 18:36:12 +0100 Received: from <a href="http://outgoing.securityfocus.com" title="http://outgoing.securityfocus.com" target="_blank">outgoing.securityfocus.com</a> ([205.206.231.27] helo=outgoing3.securityfocus.com) 	by <a href="http://lt.network5.net" title="http://lt.network5.net" target="_blank">lt.network5.net</a> with esmtp (Exim 4.43) 	id 1LrFDX-00055K-TP 	for email@address; Tue, 07 Apr 2009 18:36:12 +0100 Received: from <a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> (<a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> [205.206.231.20]) 	by <a href="http://outgoing3.securityfocus.com" title="http://outgoing3.securityfocus.com" target="_blank">outgoing3.securityfocus.com</a> (Postfix) with QMQP 	id DE1F223736A; Tue,  7 Apr 2009 10:33:59 -0600 (MDT) Mailing-List: contact <a href="mailto:bugtraq-help@securityfocus.com;" title="mailto:bugtraq-help@securityfocus.com;">bugtraq-help@securityfocus.com;</a> run by ezmlm Precedence: bulk List-Id: &lt;bugtraq.list-id.securityfocus.com&gt; List-Post: &lt;mailto:bugtraq@securityfocus.com&gt; List-Help: &lt;mailto:bugtraq-help@securityfocus.com&gt; List-Unsubscribe: &lt;mailto:bugtraq-unsubscribe@securityfocus.com&gt; List-Subscribe: &lt;mailto:bugtraq-subscribe@securityfocus.com&gt; Delivered-To: mailing list <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Delivered-To: moderator for <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Received: (qmail 13130 invoked from network); 7 Apr 2009 15:38:43 -0000 Reply-To: Ubuntu Security &lt;security@ubuntu.com&gt; Cc: <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a>, <a href="mailto:full-disclosure@lists.grok.org.uk" title="mailto:full-disclosure@lists.grok.org.uk">full-disclosure@lists.grok.org.uk</a> X-Original-To: <a href="mailto:marc.deslauriers@cleanmail.canonical.com" title="mailto:marc.deslauriers@cleanmail.canonical.com">marc.deslauriers@cleanmail.canonical.com</a> X-Mailcontrol-Inbound:   uq3drnD2P+ps5SfEb0fvr78+NoP1DHBZwGqKpaXB2eTgNv8D6KLIxb8+NoP1DHBZ8VSaBg0k0xw= X-Spam-Score: -15 X-Scanned-By: MailControl A_08_51_00 (<a href="http://www.mailcontrol.com" title="http://www.mailcontrol.com" target="_blank">www.mailcontrol.com</a>) on 10.74.0.154 Content-Type: multipart/signed; micalg=&quot;pgp-sha1&quot;; protocol=&quot;application/pgp-signature&quot;; boundary=&quot;=-EkOmRjtPenBTJ5mcQ7pH&quot; Message-Id: &lt;1239118997.5645.37.camel@mdlinux.technorage.com&gt; Mime-Version: 1.0 X-Mailer: Evolution 2.26.0  X-IMAPbase: 1176125385 8696 Status: O X-UID: 8696 Content-Length: 36874 X-Keywords:                                                                                                    </p>
<p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/postgresql-vulnerability-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PostgreSQL vulnerability</title>
		<link>http://sechero.com/postgresql-vulnerability/</link>
		<comments>http://sechero.com/postgresql-vulnerability/#comments</comments>
		<pubDate>Tue, 07 Apr 2009 15:43:17 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Postgresql]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://sechero.com/postgresql-vulnerability/</guid>
		<description><![CDATA[[USN-753-1] PostgreSQL vulnerability Posted by Marc Deslauriers on Apr 07 =========================================================== Ubuntu Security Notice USN-753-1 April 07, 2009 postgresql-8.1, postgresql-8.3 vulnerability CVE-2009-0922 =========================================================== A security issue affects the following Ubuntu&#8230; URL: http://seclists.org/fulldisclosure/2009/Apr/0058.html]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/fulldisclosure/2009/Apr/0058.html">[USN-753-1] PostgreSQL vulnerability</a></h1>
</p>
<p>Posted by Marc Deslauriers on Apr 07
</p>
<p>
<p> =========================================================== <br /> Ubuntu Security Notice USN-753-1             April 07, 2009 <br /> postgresql-8.1, postgresql-8.3 vulnerability <br /> CVE-2009-0922 <br /> =========================================================== <br /> 
<p>A security issue affects the following Ubuntu&#8230;
<p>URL: <a href="http://seclists.org/fulldisclosure/2009/Apr/0058.html">http://seclists.org/fulldisclosure/2009/Apr/0058.html</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/postgresql-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Next-gen SQL injection opens server door</title>
		<link>http://sechero.com/next-gen-sql-injection-opens-server-door/</link>
		<comments>http://sechero.com/next-gen-sql-injection-opens-server-door/#comments</comments>
		<pubDate>Mon, 06 Apr 2009 00:51:39 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Postgresql]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://sechero.com/next-gen-sql-injection-opens-server-door/</guid>
		<description><![CDATA[Next-gen SQL injection opens server door A vulnerability estimated to affect more than 1 in 10 websites could go lethal with the finding that it can be used to reliably take complete control of the site&#8217;s underlying server. Research to be presented at the Black Hat security conference in Amsterdam later this month will show [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=30753">Next-gen SQL injection opens server door</a></h1>
</p>
<p>A vulnerability estimated to affect more than 1 in 10 websites could go lethal with the finding that it can be used to reliably take complete control of the site&#8217;s underlying server.</p>
<p>Research to be presented at the Black Hat security conference in Amsterdam later this month will show how so-called SQL injection attacks open the door to much more serious exploits that give hackers unfettered access to a website&#8217;s database and the operating system that runs it. Penetration tester Bernardo Damele Assumpcao Guimaraes says his techniques prey on design flaws in three of the most popular databases, including MySQL, PostgreSQL, and Microsoft SQL Server.</p>
<p>SQL injections are the result of applications that fail to vet user-supplied input entered into search boxes and other website fields. Hackers can abuse this failure to access private information by entering valid commands that get executed by a website&#8217;s back-end database. Over the past five years, SQL injections have tripped up some of the world&#8217;s most sensitive sites, including the Department of Homeland Security, embassies, banks, and security companies.
<p>URL: <a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=30753">http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=30753</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/next-gen-sql-injection-opens-server-door/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>[ MDVSA-2009:079 ] postgresql</title>
		<link>http://sechero.com/mdvsa-2009079-postgresql/</link>
		<comments>http://sechero.com/mdvsa-2009079-postgresql/#comments</comments>
		<pubDate>Mon, 23 Mar 2009 19:44:42 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Bugtraq]]></category>
		<category><![CDATA[Postgresql]]></category>

		<guid isPermaLink="false">http://sechero.com/mdvsa-2009079-postgresql/</guid>
		<description><![CDATA[Bugtraq: [ MDVSA-2009:079 ] postgresql [ MDVSA-2009:079 ] postgresql URL: http://www.securityfocus.com/archive/1/502056]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.securityfocus.com/archive/1/502056">Bugtraq: [ MDVSA-2009:079 ] postgresql</a></h1>
</p>
<p>[ MDVSA-2009:079 ] postgresql
<p>URL: <a href="http://www.securityfocus.com/archive/1/502056">http://www.securityfocus.com/archive/1/502056</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/mdvsa-2009079-postgresql/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>postgresql</title>
		<link>http://sechero.com/postgresql/</link>
		<comments>http://sechero.com/postgresql/#comments</comments>
		<pubDate>Mon, 23 Mar 2009 17:54:00 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Postgresql]]></category>

		<guid isPermaLink="false">http://sechero.com/postgresql/</guid>
		<description><![CDATA[[ MDVSA-2009:079 ] postgresql Posted by security_at_mandriva.com on Mar 23 &#160;_______________________________________________________________________ &#160;Mandriva Linux Security Advisory MDVSA-2009:079 &#160;http://www.mandriva.com/security/ &#160;_______________________________________________________________________ &#160;Package :&#8230; URL: http://seclists.org/fulldisclosure/2009/Mar/0322.html]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/fulldisclosure/2009/Mar/0322.html">[ MDVSA-2009:079 ] postgresql</a></h1>
</p>
<p>Posted by security_at_mandriva.com on Mar 23
</p>
<p>
<p>&nbsp;_______________________________________________________________________ <br /> 
<p>&nbsp;Mandriva Linux Security Advisory                         MDVSA-2009:079 <br /> &nbsp;http://www.mandriva.com/security/ <br /> &nbsp;_______________________________________________________________________ <br /> 
<p>&nbsp;Package :&#8230;
<p>URL: <a href="http://seclists.org/fulldisclosure/2009/Mar/0322.html">http://seclists.org/fulldisclosure/2009/Mar/0322.html</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/postgresql/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PostgreSQL Conversion Encoding Remote Denial of Service Vulnerability</title>
		<link>http://sechero.com/postgresql-conversion-encoding-remote-denial-of-service-vulnerability/</link>
		<comments>http://sechero.com/postgresql-conversion-encoding-remote-denial-of-service-vulnerability/#comments</comments>
		<pubDate>Mon, 23 Mar 2009 00:00:00 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Postgresql]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://sechero.com/postgresql-conversion-encoding-remote-denial-of-service-vulnerability/</guid>
		<description><![CDATA[Vuln: PostgreSQL Conversion Encoding Remote Denial of Service Vulnerability PostgreSQL Conversion Encoding Remote Denial of Service Vulnerability URL: http://www.securityfocus.com/bid/34090]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.securityfocus.com/bid/34090">Vuln: PostgreSQL Conversion Encoding Remote Denial of Service Vulnerability</a></h1>
</p>
<p>PostgreSQL Conversion Encoding Remote Denial of Service Vulnerability
<p>URL: <a href="http://www.securityfocus.com/bid/34090">http://www.securityfocus.com/bid/34090</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/postgresql-conversion-encoding-remote-denial-of-service-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>0922 (postgresql)</title>
		<link>http://sechero.com/0922-postgresql/</link>
		<comments>http://sechero.com/0922-postgresql/#comments</comments>
		<pubDate>Tue, 17 Mar 2009 00:00:00 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[Postgresql]]></category>

		<guid isPermaLink="false">http://sechero.com/0922-postgresql/</guid>
		<description><![CDATA[CVE-2009-0922 (postgresql) PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests. URL: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0922]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0922">CVE-2009-0922 (postgresql)</a></h1>
</p>
<p>PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests.
<p>URL: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0922">http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0922</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/0922-postgresql/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

