SCIENTIFIC-LINUX-ERRATA Archives

September 2017

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Condense Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Content-Type:
text/plain; charset="utf-8"
Date:
Thu, 14 Sep 2017 14:44:30 -0000
Reply-To:
Subject:
MIME-Version:
1.0
Message-ID:
Content-Transfer-Encoding:
7bit
Sender:
Security Errata for Scientific Linux <[log in to unmask]>
From:
Pat Riehecky <[log in to unmask]>
Parts/Attachments:
text/plain (47 lines)
Synopsis:          Moderate: postgresql security update
Advisory ID:       SLSA-2017:2728-1
Issue Date:        2017-09-14
CVE Numbers:       CVE-2017-7546
                   CVE-2017-7547
--

The following packages have been upgraded to a later upstream version:
postgresql (9.2.23).

Security Fix(es):

* It was found that authenticating to a PostgreSQL database account with
an empty password was possible despite libpq's refusal to send an empty
password. A remote attacker could potentially use this flaw to gain access
to database accounts with empty passwords. (CVE-2017-7546)

* An authorization flaw was found in the way PostgreSQL handled access to
the pg_user_mappings view on foreign servers. A remote, authenticated
attacker could potentially use this flaw to retrieve passwords from the
user mappings defined by the foreign server owners without actually having
the privileges to do so. (CVE-2017-7547)
--

SL7
  x86_64
    postgresql-debuginfo-9.2.23-1.el7_4.i686.rpm
    postgresql-debuginfo-9.2.23-1.el7_4.x86_64.rpm
    postgresql-libs-9.2.23-1.el7_4.i686.rpm
    postgresql-libs-9.2.23-1.el7_4.x86_64.rpm
    postgresql-9.2.23-1.el7_4.i686.rpm
    postgresql-9.2.23-1.el7_4.x86_64.rpm
    postgresql-contrib-9.2.23-1.el7_4.x86_64.rpm
    postgresql-devel-9.2.23-1.el7_4.i686.rpm
    postgresql-devel-9.2.23-1.el7_4.x86_64.rpm
    postgresql-docs-9.2.23-1.el7_4.x86_64.rpm
    postgresql-plperl-9.2.23-1.el7_4.x86_64.rpm
    postgresql-plpython-9.2.23-1.el7_4.x86_64.rpm
    postgresql-pltcl-9.2.23-1.el7_4.x86_64.rpm
    postgresql-server-9.2.23-1.el7_4.x86_64.rpm
    postgresql-static-9.2.23-1.el7_4.i686.rpm
    postgresql-static-9.2.23-1.el7_4.x86_64.rpm
    postgresql-test-9.2.23-1.el7_4.x86_64.rpm
    postgresql-upgrade-9.2.23-1.el7_4.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2