Gentoo Archives: gentoo-announce

From: Kristian Fiskerstrand <k_f@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] [ GLSA 201408-15 ] PostgreSQL: Multiple vulnerabilities
Date: Fri, 29 Aug 2014 23:49:55
Message-Id: 54010E03.20908@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201408-15
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: PostgreSQL: Multiple vulnerabilities
9 Date: August 29, 2014
10 Bugs: #456080, #463884, #501946
11 ID: 201408-15
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in PostgreSQL, the worst of
19 which may allow remote Denial of Service.
20
21 Background
22 ==========
23
24 PostgreSQL is an open source object-relational database management
25 system.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 dev-db/postgresql-server
34 < 9.3.3 *>= 8.4.20
35 *>= 9.1.12
36 *>= 9.2.7
37 *>= 9.0.16
38 >= 9.3.3
39
40 Description
41 ===========
42
43 Multiple vulnerabilities have been discovered in PostgreSQL. Please
44 review the CVE identifiers referenced below for details.
45
46 Impact
47 ======
48
49 A remote authenticated attacker may be able to create a Denial of
50 Service condition, bypass security restrictions, or have other
51 unspecified impact.
52
53 Workaround
54 ==========
55
56 There is no known workaround at this time.
57
58 Resolution
59 ==========
60
61 All PostgreSQL 9.3 users should upgrade to the latest version:
62
63 # emerge --sync
64 # emerge --ask --oneshot --verbose ">=dev-db/postgresql-server-9.3.3"
65
66 All PostgreSQL 9.2 users should upgrade to the latest version:
67
68 # emerge --sync
69 # emerge --ask --oneshot --verbose ">=dev-db/postgresql-server-9.2.7"
70
71 All PostgreSQL 9.1 users should upgrade to the latest version:
72
73 # emerge --sync
74 # emerge --ask --oneshot -v ">=dev-db/postgresql-server-9.1.12"
75
76 All PostgreSQL 9.0 users should upgrade to the latest version:
77
78 # emerge --sync
79 # emerge --ask --oneshot -v ">=dev-db/postgresql-server-9.0.16"
80
81 All PostgreSQL 8.4 users should upgrade to the latest version:
82
83 # emerge --sync
84 # emerge --ask --oneshot -v ">=dev-db/postgresql-server-8.4.20"
85
86 References
87 ==========
88
89 [ 1 ] CVE-2013-0255
90 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0255
91 [ 2 ] CVE-2013-1899
92 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1899
93 [ 3 ] CVE-2013-1900
94 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1900
95 [ 4 ] CVE-2013-1901
96 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1901
97 [ 5 ] CVE-2014-0060
98 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0060
99 [ 6 ] CVE-2014-0061
100 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0061
101 [ 7 ] CVE-2014-0062
102 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0062
103 [ 8 ] CVE-2014-0063
104 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0063
105 [ 9 ] CVE-2014-0064
106 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0064
107 [ 10 ] CVE-2014-0065
108 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0065
109 [ 11 ] CVE-2014-0066
110 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0066
111 [ 12 ] CVE-2014-2669
112 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-2669
113
114 Availability
115 ============
116
117 This GLSA and any updates to it are available for viewing at
118 the Gentoo Security Website:
119
120 http://security.gentoo.org/glsa/glsa-201408-15.xml
121
122 Concerns?
123 =========
124
125 Security is a primary focus of Gentoo Linux and ensuring the
126 confidentiality and security of our users' machines is of utmost
127 importance to us. Any security concerns should be addressed to
128 security@g.o or alternatively, you may file a bug at
129 https://bugs.gentoo.org.
130
131 License
132 =======
133
134 Copyright 2014 Gentoo Foundation, Inc; referenced text
135 belongs to its owner(s).
136
137 The contents of this document are licensed under the
138 Creative Commons - Attribution / Share Alike license.
139
140 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature