Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 2120-1] New postgresql-8.3 packages fix privilege escal

    From Florian Weimer@1:229/2 to All on Tue Oct 12 22:50:01 2010
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-2120-1 [email protected] http://www.debian.org/security/ Florian Weimer October 12, 2010 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : postgresql-8.3
    Vulnerability : privilege escalation
    Problem type : remote
    Debian-specific: no
    CVE Id(s) : CVE-2010-3433

    Tim Bunce discovered that PostgreSQL, a database server software, does
    not properly separate interpreters for server-side stored procedures
    which run in different security contexts. As a result, non-privileged authenticated database users might gain additional privileges.

    Note that this security update may impact intended communication through
    global variables between stored procedures. It might be necessary to
    convert these functions to run under the plperlu or pltclu languages,
    with database superuser privileges.

    This security update also includes unrelated bug fixes from PostgreSQL
    8.3.12.

    For the stable distribution (lenny), this problem has been fixed in
    version 8.3_8.3.12-0lenny1.

    For the unstable distribution (sid), this problem has been fixed in
    version 8.4.5-1 of the postgresql-8.4 package.

    We recommend that you upgrade your PostgreSQL packages.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql-8.3_8.3.12-0lenny1.dsc
    Size/MD5 checksum: 2313 1663c4c9915f51a31ff6e6b7b3bda545
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql-8.3_8.3.12.orig.tar.gz
    Size/MD5 checksum: 13955500 03b56e23c3bcdc36eee3156334b8b97b
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql-8.3_8.3.12-0lenny1.diff.gz
    Size/MD5 checksum: 52479 e39048a272b6085ad0dce1933a1b1f5b

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql-doc_8.3.12-0lenny1_all.deb
    Size/MD5 checksum: 273756 95f2dc5525e464769715c302d9141df4
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql-contrib_8.3.12-0lenny1_all.deb
    Size/MD5 checksum: 273824 0c762a2fed4bf2b85120b4fc6a3c5d09
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql-doc-8.3_8.3.12-0lenny1_all.deb
    Size/MD5 checksum: 2213230 61228c350de23b18674fc3a2b0d11e44
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql_8.3.12-0lenny1_all.deb
    Size/MD5 checksum: 273944 b89079dac539bbbaed5794bee7f4d3c3
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql-client_8.3.12-0lenny1_all.deb
    Size/MD5 checksum: 273928 744cf8e343f7c1c658eb64f976797736

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql-plpython-8.3_8.3.12-0lenny1_alpha.deb
    Size/MD5 checksum: 293706 41c14c7e0ea6dc1f6b4015fa0b3bdc9a
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql-contrib-8.3_8.3.12-0lenny1_alpha.deb
    Size/MD5 checksum: 638416 e3c55350fc57d889281157d9047da119
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/libpq-dev_8.3.12-0lenny1_alpha.deb
    Size/MD5 checksum: 498186 27c76b0e919d5d98d5573dd3cf8a29b4
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql-client-8.3_8.3.12-0lenny1_alpha.deb
    Size/MD5 checksum: 1720192 853975a17102b21ae9bcfe8ada0e8f20
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/libpq5_8.3.12-0lenny1_alpha.deb
    Size/MD5 checksum: 412750 6514158a601f1f553c2930a647f777a1
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/libecpg-compat3_8.3.12-0lenny1_alpha.deb
    Size/MD5 checksum: 282464 ceca3e409d28a80f4fc409a01f605065
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql-pltcl-8.3_8.3.12-0lenny1_alpha.deb
    Size/MD5 checksum: 292584 0435ab52cdf05454cc911432c03276fa
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql-server-dev-8.3_8.3.12-0lenny1_alpha.deb
    Size/MD5 checksum: 850022 2ff3573cbdd9dd0d89666a619c7e43b9
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/libecpg6_8.3.12-0lenny1_alpha.deb
    Size/MD5 checksum: 302546 e1dfd28c264c5f99ce6e6e7b25500b61
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/libecpg-dev_8.3.12-0lenny1_alpha.deb
    Size/MD5 checksum: 496608 e75ba2ed5ddbc07fda238362eb338704
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql-plperl-8.3_8.3.12-0lenny1_alpha.deb
    Size/MD5 checksum: 303562 63f271eb8cce73be1f042c6c31e2224f
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql-8.3_8.3.12-0lenny1_alpha.deb
    Size/MD5 checksum: 5292026 c90ade8e22f2a466495af72b640582b0
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/libpgtypes3_8.3.12-0lenny1_alpha.deb
    Size/MD5 checksum: 303396 1048e079e19085fb49d8e8879b0c7682

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql-server-dev-8.3_8.3.12-0lenny1_amd64.deb
    Size/MD5 checksum: 845666 571a85c907cd1049eb69c0a173ea229c
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/libpgtypes3_8.3.12-0lenny1_amd64.deb
    Size/MD5 checksum: 303486 1f72dfeb519ddbd0bbcda4adc7ac9fcd
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/libpq-dev_8.3.12-0lenny1_amd64.deb
    Size/MD5 checksum: 480076 4fb675f2161719be5c34e6a3ae3f493a
    http://security.debian.org/pool/updates/main/p/postgresql-8.3/postgresql-8.3_8.3.12-0lenny1_amd64.deb
    Size/MD5 checksum: 5396674 fb795f5e2f82bd737dc5b683ae762f2c

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
    • Centurion
      Fri Jun 5 22:28:01 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Fri Jun 5 17:52:51 2026
      from Sheboygan, Wi via Telnet
    • Gwylbert
      Fri Jun 5 06:28:52 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Thu Jun 4 23:42:23 2026
      from Berea, Ohio via Telnet
    • Michal Wronka
      Thu Jun 4 23:19:58 2026
      from Wroclaw, Poland via Telnet
    • Michal Wronka
      Thu Jun 4 23:17:20 2026
      from Wroclaw, Poland via SSH
    • Michal Wronka
      Thu Jun 4 23:13:51 2026
      from Wroclaw, Poland via SSH
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 714
    Nodes: 16 (2 / 14)
    Uptime: 142:11:22
    Calls: 12,088
    Calls today: 1
    Files: 14,998
    Messages: 6,517,451

© >>> Magnum BBS <<<, 2026