SCIENTIFIC-LINUX-ERRATA Archives

September 2017

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Thu, 14 Sep 2017 14:44:30 -0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (47 lines)
Synopsis:          Moderate: postgresql security update
Advisory ID:       SLSA-2017:2728-1
Issue Date:        2017-09-14
CVE Numbers:       CVE-2017-7546
                   CVE-2017-7547
--

The following packages have been upgraded to a later upstream version:
postgresql (9.2.23).

Security Fix(es):

* It was found that authenticating to a PostgreSQL database account with
an empty password was possible despite libpq's refusal to send an empty
password. A remote attacker could potentially use this flaw to gain access
to database accounts with empty passwords. (CVE-2017-7546)

* An authorization flaw was found in the way PostgreSQL handled access to
the pg_user_mappings view on foreign servers. A remote, authenticated
attacker could potentially use this flaw to retrieve passwords from the
user mappings defined by the foreign server owners without actually having
the privileges to do so. (CVE-2017-7547)
--

SL7
  x86_64
    postgresql-debuginfo-9.2.23-1.el7_4.i686.rpm
    postgresql-debuginfo-9.2.23-1.el7_4.x86_64.rpm
    postgresql-libs-9.2.23-1.el7_4.i686.rpm
    postgresql-libs-9.2.23-1.el7_4.x86_64.rpm
    postgresql-9.2.23-1.el7_4.i686.rpm
    postgresql-9.2.23-1.el7_4.x86_64.rpm
    postgresql-contrib-9.2.23-1.el7_4.x86_64.rpm
    postgresql-devel-9.2.23-1.el7_4.i686.rpm
    postgresql-devel-9.2.23-1.el7_4.x86_64.rpm
    postgresql-docs-9.2.23-1.el7_4.x86_64.rpm
    postgresql-plperl-9.2.23-1.el7_4.x86_64.rpm
    postgresql-plpython-9.2.23-1.el7_4.x86_64.rpm
    postgresql-pltcl-9.2.23-1.el7_4.x86_64.rpm
    postgresql-server-9.2.23-1.el7_4.x86_64.rpm
    postgresql-static-9.2.23-1.el7_4.i686.rpm
    postgresql-static-9.2.23-1.el7_4.x86_64.rpm
    postgresql-test-9.2.23-1.el7_4.x86_64.rpm
    postgresql-upgrade-9.2.23-1.el7_4.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2