• [SECURITY] [DSA 2658-1] postgresql-9.1 security update

    From Giuseppe Iuculano@1:229/2 to All on Thu Apr 4 16:20:01 2013
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2658-1 [email protected] http://www.debian.org/security/ Giuseppe Iuculano
    April 04, 2013 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : postgresql-9.1
    Vulnerability : several
    Problem type : remote
    Debian-specific: no
    CVE ID : CVE-2013-1899 CVE-2013-1900 CVE-2013-1901
    Debian Bug : 704479

    Several vulnerabilities were discovered in PostgreSQL database server.

    CVE-2013-1899

    Mitsumasa Kondo and Kyotaro Horiguchi of NTT Open Source Software Center
    discovered that it was possible for a connection request containing a
    database name that begins with "-" to be crafted that can damage or destroy
    files within a server's data directory. Anyone with access to the port the
    PostgreSQL server listens on can initiate this request.

    CVE-2013-1900

    Random numbers generated by contrib/pgcrypto functions may be easy for
    another database user to guess.

    CVE-2013-1901

    An unprivileged user could run commands that could interfere with
    in-progress backups

    For the stable distribution (squeeze), postgresql-9.1 is not available. DSA-2657-1 has been released for CVE-2013-1900 affecting posgresql-8.4.

    For the testing distribution (wheezy), these problems have been fixed in version 9.1.9-0wheezy1.

    For the unstable distribution (sid), these problems have been fixed in
    version 9.1.9-1.

    We recommend that you upgrade your postgresql-9.1 packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.12 (GNU/Linux)

    iEYEARECAAYFAlFdiOoACgkQNxpp46476arL3gCfbt0Lqp7YSg4erOgv+GwM5Kxb bQYAn2V5DjfmzTNOanLDYQDFuQHdO3+5
    =Ptsq
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)