First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 152783
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Raphael Marichez <falco@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 152783 depends on: Show dependency tree
Bug 152783 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-10-25 06:53 0000
Hello postgreSQL team, a little DoS vulnerability with the corrected versions
below:

Posted on 2006-10-16
Posted by josh@postgresql.org

The PostgreSQL project today is releasing the following minor versions, which
fix three different crash vulnerabilities as well as an assortment of minor
issues. Users of all PostgreSQL versions are urged to upgrade at the earliest
opportunity.

The versions being released are: 8.1.5, 8.0.9, 7.4.14, 7.3.16. These are
cumulative patch releases which simply replace the PostgreSQL binaries for
major versions 8.1, 8.0, 7.4 and 7.3. Note that users of versions 7.4.0, 7.4.1,
8.0.0 and 8.0.1 may have to take additional steps in the course of upgrading --
see the release notes for details.

Release Notes
Download

The three crash conditions are not considered critical vulnerabilities, because
all three require authenticated access to the database with the ability to run
ad-hoc queries, and none can be exploited for privilege escalation. As a
result, we have NOT filed a CVE for these issues.

Source for these releases is currently available, as well as binaries for
Windows and some distributions of Linux. Binaries for Solaris, other Linuxen,
and OSX should be obtained from their respective vendors.

------- Comment #1 From Raphael Marichez 2006-11-03 06:05:06 0000 -------
chtekk or dev-zero any news here? please advise

------- Comment #2 From Tiziano Müller 2006-11-04 02:09:15 0000 -------
Sorry for the delay. I think that we can release the version bump this weekend.

We (chtekk and I) have to decide whether and how some improvements of the
ebuilds we have in the overlay should be back-ported to the ebuilds in the tree
for the new version.

After the version bump, I'll open a stabilization-bug with the request to
stable the new postgresql-versions within 7-10 days. This is a reasonable
duration since it's not a critical vulnerability and should be manageable by
the arch-teams.

------- Comment #3 From Raphael Marichez 2006-11-04 04:35:15 0000 -------
(In reply to comment #2)
> Sorry for the delay. I think that we can release the version bump this weekend.

thanks

> 
> We (chtekk and I) have to decide whether and how some improvements of the
> ebuilds we have in the overlay should be back-ported to the ebuilds in the tree
> for the new version.

as you want :)



> After the version bump, I'll open a stabilization-bug with the request to
> stable the new postgresql-versions within 7-10 days. This is a reasonable
> duration since it's not a critical vulnerability and should be manageable by
> the arch-teams.

yes OK

------- Comment #4 From Sune Kloppenborg Jeppesen 2006-11-20 23:19:34 0000 -------
Pulling in herd for advise.

------- Comment #5 From Raphael Marichez 2006-12-14 03:05:47 0000 -------
Hi arches, please remove yourself from the Cc: list when you stabilize the
targetted versions, as usual.

Target keywords are:

8.0.9(-r1)?  on all Cced arches (the maintainer wishes 8.0.9-r1)
7.4.14 on all Cced arches
7.3.16 on all Cced arches except PPC64


8.1.15 is not needed in the security scope.

There's a dependency with dev-db/libpq, see bug 158075.

------- Comment #6 From Raphael Marichez 2006-12-14 03:06:30 0000 -------
removing X86 from Cc for our statistics, sorry for the spam :)

------- Comment #7 From Raphael Marichez 2006-12-14 10:07:22 0000 -------
*** Bug 158075 has been marked as a duplicate of this bug. ***

------- Comment #8 From Raphael Marichez 2006-12-14 10:09:54 0000 -------
Arches everything is handled here now:

dev-db/postgresql:
8.0.9-r1  on all Cced arches
7.4.14 on all Cced arches
7.3.16 on all Cced arches except PPC64

and dev-db/libpq  as a dependency

thanks

------- Comment #9 From Raphael Marichez 2006-12-14 10:10:56 0000 -------
spam, spam...

------- Comment #10 From Markus Rothe 2006-12-14 12:16:06 0000 -------
ppc64 stable

------- Comment #11 From Tobias Scherbaum 2006-12-17 00:09:30 0000 -------
ppc stable

------- Comment #12 From Jason Wever (RETIRED) 2006-12-17 10:12:03 0000 -------
SPARC stable

------- Comment #13 From Bryan Østergaard (RETIRED) 2006-12-17 13:03:20 0000 -------
Stable on Alpha + ia64.

------- Comment #14 From Konstantin Arkhipov 2006-12-17 13:37:49 0000 -------
amd64 stable.

------- Comment #15 From René Nussbaumer 2006-12-17 14:04:55 0000 -------
stable on hppa.

------- Comment #16 From Raphael Marichez 2006-12-17 15:19:53 0000 -------
(In reply to comment #12)
> SPARC stable
> 

hi Jason,

postgresql-7.3.16 seems to be missing: is it expected?

------- Comment #17 From Raphael Marichez 2006-12-17 15:20:54 0000 -------
Security team: Time To Vote

I vote no because of the needed authentication before triggering the DoS

------- Comment #18 From Jason Wever (RETIRED) 2006-12-17 18:58:28 0000 -------
Looks like I goofed on 7.3.16.  It's fixed now.  Thanks.

------- Comment #19 From Sune Kloppenborg Jeppesen 2006-12-17 22:17:50 0000 -------
I tend to vote NO.

------- Comment #20 From Wolf Giesen (RETIRED) 2006-12-17 22:41:43 0000 -------
Not sure about this one. Authentication is no real criteria IMHO, since every
stupid webabb uses an authenticated connection. Unless somebody can enlighten
me on the exact requirement to exploit this I tend to vote YES.

------- Comment #21 From Raphael Marichez 2006-12-28 09:04:07 0000 -------
closing with noglsa since there wasn't any "Yes". Feel free to reopen if you
disagree.

As usual, arm, mips, s390 and sh, don't forget to mark stable the new version
at your convenience.

First Last Prev Next    No search results available      Search page      Enter new bug