Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 68865 - Postgresql Upgrade Available for "insecure creation of temporary files"
Summary: Postgresql Upgrade Available for "insecure creation of temporary files"
Status: RESOLVED DUPLICATE of bug 66371
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.postgresql.org/news/234.html
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-10-25 10:38 UTC by Scott Langley
Modified: 2007-09-22 23:23 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Scott Langley 2004-10-25 10:38:41 UTC
"PostgreSQL Security Release(s) for 7.2, 7.3 and 7.4
Posted on 2004-10-23
Posted by press at PostgreSQL.org

In order to address a recent security report from iDefence, we have released 3 new "point" releases: 7.2.6, 7.3.8 and 7.4.6

Although rated only a Medium risk, according to their web site: "A vulnerability exists due to the insecure creation of temporary files, which could possibly let a malicious user overwrite arbitrary files."

Also in these releases is a potential 'data loss' bug that was recently identified:

* Repair possible failure to update hint bits on disk
Under rare circumstances this oversight could lead to "could not access transaction status" failures, which qualifies it as a potential-data-loss bug."
Comment 1 Rajiv Aaron Manglani (RETIRED) gentoo-dev 2004-10-25 11:03:59 UTC
the vulnerability has already been addressed in bug #66371 and glsa 200410-16:
http://www.gentoo.org/security/en/glsa/glsa-200410-16.xml

update to postgresql >= 7.4.5-r2 or 7.3.7-r2.

postgresql 7.3.8 and 7.4.6 are already in portage, currently marked unstable.


*** This bug has been marked as a duplicate of 66371 ***