First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 134168
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Shirish Jain <gentoo@getafix.net>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
postgresql-8.1.4-overlay.tar.bz2 overlay for postgresql-8.1.4 application/octet-stream John Jay 2006-05-26 14:54 0000 44.99 KB Details
postgresql-8.1.4.ebuild 8.1.4 ebuild text/plain John Jay 2006-05-26 15:27 0000 7.58 KB Details
postgresql-8.1.4-gentoo.patch 8.1.4 gentoo patch patch John Jay 2006-05-26 15:28 0000 1.10 KB Details | Diff
postgresql.init-8.1.4 8.1.4 init text/plain John Jay 2006-05-26 15:29 0000 1.14 KB Details
postgresql-8.1.4-sh.patch 8.1.4 spinlock patch patch John Jay 2006-05-26 15:29 0000 780 bytes Details | Diff
postgresql.conf-8.1.4 8.1.4 conf text/plain John Jay 2006-05-26 15:32 0000 390 bytes Details
libpq-8.1.4.ebuild libpq-8.1.4 ebuild text/plain John Jay 2006-05-26 15:32 0000 3.13 KB Details
libpq-8.1.4-gentoo.patch libpq-8.1.4 patch text/plain John Jay 2006-05-26 15:33 0000 2.34 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 134168 depends on: 135187 Show dependency tree
Bug 134168 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-05-23 20:59 0000
folks, please refer here http://www.postgresql.org/about/news.561 for the
recent urgent security release from Postgres on all the streams. New versions
releasd are 8.1.4, 8.0.8, 7.4.13 and 7.3.15.

its also on Slashdot. I could find ebuilds to upgrade to above versions, I did
search here as well, alas, no avail. Hence this bug report.

regards

Shirish

------- Comment #1 From Aquila 2006-05-24 00:56:23 0000 -------
I can support this request. This is urgent because the slashdot article
describes possible exploits...

------- Comment #2 From Wolf Giesen (RETIRED) 2006-05-24 01:08:36 0000 -------
Definitely urgent, it's all over the news.

------- Comment #3 From Raphael Marichez 2006-05-24 02:01:31 0000 -------
Hi PGSQL team,

please take care of it, and please update the metadata file with a
pgsql-bugs@gentoo.org mention. (herd is postgresql and postgresql@gentoo.org
doesn't exist)

------- Comment #4 From Stefan Cornelius (RETIRED) 2006-05-24 07:52:24 0000 -------
(little cleanup, was forced to specify a comment by bugzie)

------- Comment #5 From Thierry Carrez (RETIRED) 2006-05-25 11:03:02 0000 -------
Wrong category

------- Comment #6 From John Jay 2006-05-26 14:54:56 0000 -------
Created an attachment (id=87591) [details]
overlay for postgresql-8.1.4

ebuild and patches for 8.1.4

------- Comment #7 From John Jay 2006-05-26 15:27:04 0000 -------
Created an attachment (id=87594) [details]
8.1.4 ebuild

------- Comment #8 From John Jay 2006-05-26 15:28:09 0000 -------
Created an attachment (id=87595) [details]
8.1.4 gentoo patch

------- Comment #9 From John Jay 2006-05-26 15:29:04 0000 -------
Created an attachment (id=87596) [details]
8.1.4 init

------- Comment #10 From John Jay 2006-05-26 15:29:55 0000 -------
Created an attachment (id=87597) [details]
8.1.4 spinlock patch

------- Comment #11 From John Jay 2006-05-26 15:32:27 0000 -------
Created an attachment (id=87598) [details]
8.1.4 conf

------- Comment #12 From John Jay 2006-05-26 15:32:59 0000 -------
Created an attachment (id=87599) [details]
libpq-8.1.4 ebuild

------- Comment #13 From John Jay 2006-05-26 15:33:23 0000 -------
Created an attachment (id=87600) [details]
libpq-8.1.4 patch

------- Comment #14 From Stefan Cornelius (RETIRED) 2006-05-30 06:45:09 0000 -------
whats up here?!

------- Comment #15 From Konstantin Arkhipov 2006-05-31 10:42:08 0000 -------
ok, libpq/postgresql - 8.1.4, 8.0.8, 7.4.13, 7.3.15 committed in portage.
8.1.4 stresstested on two machines (x86/amd64), other's are only known to
compile and start.

------- Comment #16 From Stefan Cornelius (RETIRED) 2006-05-31 10:49:28 0000 -------
Arches, a lot of work coming up: please test and stable versions 8.1.4, 8.0.8,
7.4.13, 7.3.15, libpq should be stabled in sync.

Last arch that goes stable, please remove old vulnerable cruft from the tree,
thanks

Also thanks to voxus for bumping.

------- Comment #17 From Gustavo Zacarias (RETIRED) 2006-05-31 12:15:47 0000 -------
Do we really wanna stable 8.1.x in this run? (no previous 8.1.x is stable)

------- Comment #18 From Stefan Cornelius (RETIRED) 2006-05-31 12:28:22 0000 -------
(In reply to comment #17)
> Do we really wanna stable 8.1.x in this run? (no previous 8.1.x is stable)

Crap I'm sorry, my fault. 8.1.x does not need to be stabled

------- Comment #19 From Markus Rothe 2006-05-31 13:21:27 0000 -------
7.4.13 and 8.0.8 stable on ppc64.

(7.3.x has no stable ppc64 keyword)

------- Comment #20 From Daniel Ceregatti 2006-05-31 15:34:31 0000 -------
I noticed the "threads" USE flag was added to 8.1.4. From what I was able to
glean from developers in #postgresql on freenode, this USE flag does absolutely
nothing for postgresql server, as it's not threaded. This USE flag is meant
only for libpq. It should be removed from the postgresql ebuild.

My 2

------- Comment #21 From Daniel Ceregatti 2006-05-31 15:34:31 0000 -------
I noticed the "threads" USE flag was added to 8.1.4. From what I was able to
glean from developers in #postgresql on freenode, this USE flag does absolutely
nothing for postgresql server, as it's not threaded. This USE flag is meant
only for libpq. It should be removed from the postgresql ebuild.

My 2¢.

Daniel

------- Comment #22 From John Jay 2006-05-31 16:46:47 0000 -------
The threads USE flag was introduced in 8.1.3...whether it has any real bearing
is another question, from the configure (line 16202):

#
# Pthreads
#
# For each platform, we need to know about any special compile and link
# libraries, and whether the normal C function names are thread-safe.
# See the comment at the top of src/port/thread.c for more information.
#

For the lazy src/port/thread.c:
[snip]
/*
 *      Threading sometimes requires specially-named versions of functions
 *      that return data in static buffers, like strerror_r() instead of
 *      strerror().  Other operating systems use pthread_setspecific()
 *      and pthread_getspecific() internally to allow standard library
 *      functions to return static data to threaded applications. And some
 *      operating systems have neither.
[/snip]

Macros for thread safety of threaded applications which use the threaded
libraries.

------- Comment #23 From John Jay 2006-05-31 16:48:13 0000 -------
[clarification] Thread safety was added in 8.1.3, the USE flag was added in
8.1.3-r1

------- Comment #24 From Thomas Cort (RETIRED) 2006-06-01 11:08:32 0000 -------
{postgres,libpq}-{7.4.13,8.0.8} stable on alpha.

7.3.15 doesn't compile. I'll file a bug for it and make this bug depend on it.

------- Comment #25 From Gustavo Zacarias (RETIRED) 2006-06-01 13:00:08 0000 -------
7.4.13 and 8.0.8 sparc stable.
7.3.15 is br0ke for us too.

------- Comment #26 From Tobias Scherbaum 2006-06-01 13:00:58 0000 -------
{postgres,libpq}-{7.4.13,8.0.8} stable on ppc.

7.3.15 also doesn't compile on ppc, I added us to that bug.

------- Comment #27 From Mark Loeser 2006-06-02 20:35:54 0000 -------
^^what all of those guys said :)

7.4.13 & 8.0.8 done on x86

------- Comment #28 From René Nussbaumer 2006-06-04 01:46:47 0000 -------
Stable on hppa. Forgot to comment this on this bug. 7.3.15 doesn't build on
hppa, too. Added us to that bug.

------- Comment #29 From Thomas Cort (RETIRED) 2006-06-04 19:07:04 0000 -------
{postgres,libpq}-{7.4.13,8.0.8} stable on amd64.

7.3.15 doesn't compile, I added us to bug #135187.

------- Comment #30 From Raphael Marichez 2006-06-25 15:47:56 0000 -------
this bug is rather old. Shouldn't we consider sending a GLSA mentionning that
the 1.3.x branch is still vulnerable ?

------- Comment #31 From Raphael Marichez 2006-06-26 00:42:47 0000 -------
> the 1.3.x branch is still vulnerable ?

not 1.3.x, but 7.3.x, of course, you have already corrected me.

------- Comment #32 From Joshua Jackson 2006-06-26 10:32:37 0000 -------
removing x86 as we've stablized the packages requested and don't see a need to
be on the bug anymore. If this is not the case and we're still on it for a
reason feel free to readd us.

------- Comment #33 From Wolf Giesen (RETIRED) 2006-06-28 22:14:34 0000 -------
Since 7.3.15 seems broken on most arches we should consider masking the 7.3
branch, since the bug is aging and we should get the GLSA out.

Jaervosz?

------- Comment #34 From Sune Kloppenborg Jeppesen 2006-06-30 08:08:14 0000 -------
@pqsql-bugs: what do you think about masking?

@arches please test and mark stable or comment. We're quite late on this one.

------- Comment #35 From Gustavo Zacarias (RETIRED) 2006-06-30 08:10:19 0000 -------
sparc has everything stable except 7.3.15

------- Comment #36 From Thomas Cort (RETIRED) 2006-06-30 09:19:52 0000 -------
(In reply to comment #33)
> @arches please test and mark stable or comment. We're quite late on this one.

As I stated in comment #28, alpha has everything stable except 7.3.15, see Bug
#135187.

------- Comment #37 From Lars Weiler (RETIRED) 2006-07-01 01:53:55 0000 -------
I think I can safely remove ppc from this bug as all mentioned ebuilds (beside
7.3.15) are stable.

------- Comment #38 From Sune Kloppenborg Jeppesen 2006-07-05 10:11:34 0000 -------
Ok, we'll release a GLSA without a fix for 7.3 (which could be masked)

------- Comment #39 From Sune Kloppenborg Jeppesen 2006-07-09 10:10:02 0000 -------
GLSA 200607-04

------- Comment #40 From Matthias Geerdsen 2006-10-19 06:23:00 0000 -------
*** Bug 151482 has been marked as a duplicate of this bug. ***

First Last Prev Next    No search results available      Search page      Enter new bug