Summary: | <dev-db/pgbouncer-1.7.2: failed auth_query lookup leads to connection as auth_user (CVE-2015-6817) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Thomas Deutschmann (RETIRED) <whissi> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | bugs, esigra, pgsql-bugs, proxy-maint, titanofold |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.openwall.com/lists/oss-security/2015/09/04/3 | ||
Whiteboard: | B1 [glsa cve] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | |||
Bug Blocks: | 550124 |
Description
Thomas Deutschmann (RETIRED)
![]() A fixed version is already in tree. @ maintainer(s): Please tell us how to proceed. Is =dev-db/pgbouncer-1.7.2 ready for stabilization? @ Arches, please test and mark stable: =dev-db/pgbouncer-1.7.2 amd64 stable x86 stable. Maintainer(s), please cleanup. Security, please add it to the existing request, or file a new one. please clean or mask the vulnerable versions. Cleanup PR: https://github.com/gentoo/gentoo/pull/3388 Cleanup via https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=21d4894c33d001a22513bb5ff7d4fae54fc41c6c New GLSA request filed. This issue was resolved and addressed in GLSA 201701-24 at https://security.gentoo.org/glsa/201701-24 by GLSA coordinator Aaron Bauman (b-man). |