Thread: CVE-2013-1899 security issue and limited IP addresses in pg_hba.conf

CVE-2013-1899 security issue and limited IP addresses in pg_hba.conf

From
Mads.Tandrup@schneider-electric.com
Date:
<font face=3D"Default Sans Serif,Verdana,Arial,Helvetica,sans-serif" size=
=3D"2">Hi AllI'm trying to understand the im=
plications of the latest security fix to postgresql [1].</di=
v>We have a setup were we in pg=5Fhba.conf have limited the allowed IP=
 addresses of the clients. But does anyone know if CVE-2013-1899 allow=
s an arbitrary attacker to use the exploits described in [1]?<br=
>We are using PostgreSQL 8.4.Best rega=
rds,Mads[1] http://www.postgresql=
.org/support/security/faq/2013-04-04/=

Re: CVE-2013-1899 security issue and limited IP addresses in pg_hba.conf

From
Devrim Gündüz
Date:
Hi,

pg_hba.conf does not have protection for this security issue.

Regards, Devrim

Mads.Tandrup@schneider-electric.com wrote:
Hi All

I'm trying to understand the implications of the latest security fix to postgresql [1].

We have a setup were we in pg_hba.conf have limited the allowed IP addresses of the clients. But does anyone know if CVE-2013-1899 allows an arbitrary attacker to use the exploits described in [1]?

We are using PostgreSQL 8.4.

Best regards,
Mads

[1] http://www.postgresql.org/support/security/faq/2013-04-04/


--
Devrim Gündüz

Re: CVE-2013-1899 security issue and limited IP addresses in pg_hba.conf

From
Bruce Momjian
Date:
On Thu, Apr  4, 2013 at 06:39:22PM +0200, Mads.Tandrup@schneider-electric.com wrote:
> Hi All
>
> I'm trying to understand the implications of the latest security fix to
> postgresql [1].
>
> We have a setup were we in pg_hba.conf have limited the allowed IP addresses of
> the clients. But does anyone know if CVE-2013-1899 allows an arbitrary attacker
> to use the exploits described in [1]?

Yes, if you were running 9.0+.  pg_hba.conf does not limit access
sufficiently, though listen_addresses does.

> We are using PostgreSQL 8.4.

8.4 does not contain the bug.

--
  Bruce Momjian  <bruce@momjian.us>        http://momjian.us
  EnterpriseDB                             http://enterprisedb.com

  + It's impossible for everything to be true. +

Re: CVE-2013-1899 security issue and limited IP addresses in pg_hba.conf

From
Mads.Tandrup@schneider-electric.com
Date:
<font face=3D"Default Sans Serif,Verdana,Arial,Helvetica,sans-serif" size=
=3D"2">Hi Bruce.Didn't catch that in the announcement.<=
/div>Thanks for clearing out the confusion.B=
est regards,Mads=