Gentoo Archives: gentoo-announce

From: Mikle Kolyada <zlogene@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201507-20 ] PostgreSQL: Multiple vulnerabilities
Date: Sat, 18 Jul 2015 13:03:09
Message-Id: 55AA4DA0.4090101@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201507-20
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: PostgreSQL: Multiple vulnerabilities
9 Date: July 18, 2015
10 Bugs: #539018, #550172
11 ID: 201507-20
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in PostgreSQL, the worst of
19 which could result in execution of arbitrary code or privilege
20 escalation.
21
22 Background
23 ==========
24
25 PostgreSQL is an open source object-relational database management
26 system.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 dev-db/postgresql < 9.4.3 *>= 9.0.21
35 *>= 9.1.17
36 *>= 9.2.12
37 *>= 9.3.8
38 >= 9.4.3
39
40 Description
41 ===========
42
43 Multiple vulnerabilities have been discovered in PostgreSQL. Please
44 review the CVE identifiers referenced below for details.
45
46 Impact
47 ======
48
49 A remote attacker could possibly execute arbitrary code with the
50 privileges of the process, cause a Denial of Service condition or
51 escalate privileges.
52
53 Workaround
54 ==========
55
56 There is no known workaround at this time.
57
58 Resolution
59 ==========
60
61 All PostgreSQL 9.0.x users should upgrade to the latest version:
62
63 # emerge --sync
64 # emerge --ask --oneshot --verbose ">=dev-db/postgresql-9.0.21"
65
66 All PostgreSQL 9.1.x users should upgrade to the latest version:
67
68 # emerge --sync
69 # emerge --ask --oneshot --verbose ">=dev-db/postgresql-9.1.17"
70
71 All PostgreSQL 9.2.x users should upgrade to the latest version:
72
73 # emerge --sync
74 # emerge --ask --oneshot --verbose ">=dev-db/postgresql-9.2.12"
75
76 All PostgreSQL 9.3.x users should upgrade to the latest version:
77
78 # emerge --sync
79 # emerge --ask --oneshot --verbose ">=dev-db/postgresql-9.3.8"
80
81 All PostgreSQL 9.4.x users should upgrade to the latest version:
82
83 # emerge --sync
84 # emerge --ask --oneshot --verbose ">=dev-db/postgresql-9.4.3"
85
86 References
87 ==========
88
89 [ 1 ] CVE-2014-8161
90 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-8161
91 [ 2 ] CVE-2015-0241
92 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0241
93 [ 3 ] CVE-2015-0242
94 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0242
95 [ 4 ] CVE-2015-0243
96 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0243
97 [ 5 ] CVE-2015-0244
98 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0244
99 [ 6 ] CVE-2015-3165
100 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3165
101 [ 7 ] CVE-2015-3166
102 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3166
103 [ 8 ] CVE-2015-3167
104 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3167
105
106 Availability
107 ============
108
109 This GLSA and any updates to it are available for viewing at
110 the Gentoo Security Website:
111
112 https://security.gentoo.org/glsa/201507-20
113
114 Concerns?
115 =========
116
117 Security is a primary focus of Gentoo Linux and ensuring the
118 confidentiality and security of our users' machines is of utmost
119 importance to us. Any security concerns should be addressed to
120 security@g.o or alternatively, you may file a bug at
121 https://bugs.gentoo.org.
122
123 License
124 =======
125
126 Copyright 2015 Gentoo Foundation, Inc; referenced text
127 belongs to its owner(s).
128
129 The contents of this document are licensed under the
130 Creative Commons - Attribution / Share Alike license.
131
132 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature