First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 165482
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Executioner <keith@email.arizona.edu>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 165482 depends on: Show dependency tree
Show dependency graph
Bug 165482 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-02-05 19:47 0000
Description:
Some vulnerabilities have been reported in PostgreSQL, which can be exploited
by malicious users to gain knowledge of potentially sensitive information and
cause a DoS (Denial of Service).

1) An unspecified error can be used to suppress certain checks, which ensure
that SQL functions return the correct data type. This can be exploited to crash
the database backend or disclose potentially sensitive information.

2) An unspecified error when changing the data type of a table column can be
exploited to crash the database backend or disclose potentially sensitive
information.

Vulnerability #1 is reported in versions 8.0, 8.1, and 8.2. Vulnerability #2 is
reported in 8.0, 8.1, 8.2, 7.3 and 7.4.

Solution:
Update to 8.2.2, 8.1.7, 8.0.11, 7.4.16, or 7.3.13.


Reproducible: Didn't try




http://www.postgresql.org/support/security

------- Comment #1 From Jakub Moc 2007-02-06 07:43:23 0000 -------
*** Bug 165562 has been marked as a duplicate of this bug. ***

------- Comment #2 From Ernst Herzberg 2007-02-06 19:45:00 0000 -------
Ooops, wait! :-)

8.1.7 and 8.2.2 are buggy, see
http://archives.postgresql.org/pgsql-hackers/2007-02/msg00286.php

------- Comment #3 From Bernd Marienfeldt 2007-02-07 15:07:13 0000 -------
See update from Postgress Developer:

http://archives.postgresql.org/pgsql-announce/2007-02/msg00008.php


Kind regards

------- Comment #4 From Martin Jackson (RETIRED) 2007-02-11 22:53:55 0000 -------
libpq and postgresql 7.3.18 have been committed to the tree.

------- Comment #5 From Raphael Marichez 2007-02-12 12:50:52 0000 -------
(In reply to comment #4)
> libpq and postgresql 7.3.18 have been committed to the tree.
> 

Thanks, perfect.

Hi arches, please test and mark stable if appropriate those ebuilds :

libpq-7.3.18
postgresql-7.3.18
libpq-7.4.16
postgresql-7.4.16
libpq-8.0.12
postgresql-8.0.12

------- Comment #6 From Raúl Porcel 2007-02-12 14:54:32 0000 -------
(In reply to comment #5)
> libpq-7.3.18
> postgresql-7.3.18
> libpq-7.4.16
> postgresql-7.4.16
> 

>>> Unpacking postgresql-opt-7.3.18.tar.bz2 to /var/tmp/portage/dev-db/libpq-7.3.18/work
 * Applying libpq-7.3.18-gentoo.patch ...

 * Failed Patch: libpq-7.3.18-gentoo.patch !
 *  ( /usr/portage/dev-db/libpq/files/libpq-7.3.18-gentoo.patch )

Same occurs with 7.4.16.

------- Comment #7 From Martin Jackson (RETIRED) 2007-02-13 01:49:11 0000 -------
The 7.3 and 7.4 problems are because I missed CVS keywords in the libpq patches
for those versions.  I've committed fixes for libpq-7.3 and 7.4, and I've
verified none of the other ebuilds have that problem.  Sorry for any confusion.

------- Comment #8 From Christian Faulhammer 2007-02-13 10:03:29 0000 -------
x86 stable

------- Comment #9 From Markus Rothe 2007-02-13 10:44:03 0000 -------
jep.. seems to work. ppc64 stable

------- Comment #10 From Gustavo Zacarias (RETIRED) 2007-02-13 15:42:21 0000 -------
sparc stable.

------- Comment #11 From Jeroen Roovers 2007-02-14 04:53:52 0000 -------
Stable for HPPA. As a side note, postgresql-7.3.18 failed the horology
regression test whilst 7.4.16 did not. I did not test this for 8.0.12 within
the scope of this bug.

------- Comment #12 From Jeroen Roovers 2007-02-14 05:02:20 0000 -------
(In reply to comment #11)
> Stable for HPPA. As a side note, postgresql-7.3.18 failed the horology
> regression test whilst 7.4.16 did not. I did not test this for 8.0.12 within
> the scope of this bug.

Found the source too: compare [1] and [2]. False alarm.

[1] http://www.postgresql.org/docs/7.3/interactive/regress-platform.html
[2] http://www.postgresql.org/docs/7.4/interactive/regress-platform.html

------- Comment #13 From Bryan Østergaard (RETIRED) 2007-02-16 12:43:29 0000 -------
Stable on Alpha + IA64.

------- Comment #14 From Tobias Scherbaum 2007-02-18 15:37:23 0000 -------
ppc stable

------- Comment #15 From Raphael Marichez 2007-03-03 23:53:59 0000 -------
Hi amd64, there is something causing trouble?

------- Comment #16 From Simon Stelling (RETIRED) 2007-03-04 11:15:11 0000 -------
(In reply to comment #15)
> Hi amd64, there is something causing trouble?

Nothing unusual. Stable on amd64.

------- Comment #17 From Stefan Cornelius (RETIRED) 2007-03-04 12:59:57 0000 -------
voting no

------- Comment #18 From Raphael Marichez 2007-03-04 21:02:26 0000 -------
mmm i don't know.... CVE-2007-0556 seems a little severe.

------- Comment #19 From Matthias Geerdsen 2007-03-05 21:14:43 0000 -------
tend to vote yes here

------- Comment #20 From Raphael Marichez 2007-03-09 22:33:52 0000 -------
another security member with interesting arguments? Otherwise i would say "yes"
too.

GLSA request filled.

------- Comment #21 From Raphael Marichez 2007-03-18 22:02:50 0000 -------
GLSA 200701-15 sent but apprently, it never hit gentoo-announce@

------- Comment #22 From Raphael Marichez 2007-03-19 00:19:49 0000 -------
GLSA 200703-15 seems to have finally reached g-announce. Closing then. Thanks
to everybody

First Last Prev Next    No search results available      Search page      Enter new bug