Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 165562 - PostgreSQL multiple vulnerabilities
Summary: PostgreSQL multiple vulnerabilities
Status: RESOLVED DUPLICATE of bug 165482
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Linux bug wranglers
URL: http://www.postgresql.org/about/news.741
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-02-06 03:53 UTC by Martin Jackson (RETIRED)
Modified: 2007-09-23 00:19 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Martin Jackson (RETIRED) gentoo-dev 2007-02-06 03:53:05 UTC
PostgreSQL Security Update Released
Posted on 2007-02-05
Posted by josh@postgresql.org

The PostgreSQL Global Development Group releases today a security update for all recent PostgreSQL versions: minor versions 8.2.2, 8.1.7, 8.0.11, 7.4.16 and 7.3.18. Because this patches a medium-risk security hole, all users are urged to upgrade at the earliest opportunity.

This release fixes CVE-2007-0555 and CVE-2007-0556. Both of these issues allow an authenticated attacker with the permissions to run arbitrary SQL to launch a denial-of-service attack or possibly read out random chunks of memory. Since attacks to require authenticated access, the security hole is only considered medium risk. You can read more about the issues on Mitre: CVE-2007-0555 CVE-2007-0556

In keeping with the PostgreSQL Project's security fix policies, this update is being released as quickly as possible: within 2 weeks of the first bug report, and within five days of developing a fix. This type of fast response is central to PostgreSQL's reputation as one of the most secure databases in the industry.
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2007-02-06 07:43:23 UTC

*** This bug has been marked as a duplicate of bug 165482 ***