Summary: | <dev-db/postgresql-server-{9.1.3,9.0.7,8.4.11,8.3.18}: Multiple Vulnerabilities (CVE-2012-{0866,0867,0868}) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Aaron W. Swenson <titanofold> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | ||
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.postgresql.org/about/news/1377/ | ||
Whiteboard: | A3 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Aaron W. Swenson
2012-02-27 14:04:07 UTC
Thanks for the bug, Aaron. Stabilization Targets: dev-db/postgresql-docs-8.3.18 dev-db/postgresql-docs-8.4.11 dev-db/postgresql-docs-9.0.7 dev-db/postgresql-docs-9.1.3 dev-db/postgresql-base-8.3.18 dev-db/postgresql-base-8.4.11 dev-db/postgresql-base-9.0.7 dev-db/postgresql-base-9.1.3 dev-db/postgresql-server-8.3.18 dev-db/postgresql-server-8.4.11 dev-db/postgresql-server-9.0.7 dev-db/postgresql-server-9.1.3 ppc done Stable for HPPA. amd64 stable Stable on alpha. ppc64 done arm stable x86 stable. Thanks ia64/s390/sh/sparc stable Thanks, everyone. GLSA request filed. PostgreSQL 8.2 has been removed from the tree. No affected versions left in tree. CVE-2012-0868 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0868): CRLF injection vulnerability in pg_dump in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows user-assisted remote attackers to execute arbitrary SQL commands via a crafted file containing object names with newlines, which are inserted into an SQL script that is used when the database is restored. CVE-2012-0867 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0867): PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters. CVE-2012-0866 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0866): CREATE TRIGGER in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 does not properly check the execute permission for trigger functions marked SECURITY DEFINER, which allows remote authenticated users to execute otherwise restricted triggers on arbitrary data by installing the trigger on an attacker-owned table. This issue was resolved and addressed in GLSA 201209-24 at http://security.gentoo.org/glsa/glsa-201209-24.xml by GLSA coordinator Sean Amoss (ackle). |