SCIENTIFIC-LINUX-ERRATA Archives

September 2012

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Connie Sieh <[log in to unmask]>
Reply To:
Connie Sieh <[log in to unmask]>
Date:
Fri, 14 Sep 2012 16:52:58 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (93 lines)
Synopsis:          Moderate: postgresql and postgresql84 security update
Issue Date:        2012-09-13
CVE Numbers:       CVE-2012-3488
                    CVE-2012-3489


It was found that the optional PostgreSQL xml2 contrib module allowed local
files and remote URLs to be read and written to with the privileges of the
database server when parsing Extensible Stylesheet Language Transformations
(XSLT). An unprivileged database user could use this flaw to read and write
to local files (such as the database's configuration files) and remote URLs
they would otherwise not have access to by issuing a specially-crafted SQL
query. (CVE-2012-3488)

It was found that the "xml" data type allowed local files and remote URLs
to be read with the privileges of the database server to resolve DTD and
entity references in the provided XML. An unprivileged database user could
use this flaw to read local files they would otherwise not have access to
by issuing a specially-crafted SQL query. Note that the full contents of
the files were not returned, but portions could be displayed to the user
via error messages. (CVE-2012-3489)

We would like to thank the PostgreSQL project for reporting these
issues. Upstream acknowledges Peter Eisentraut as the original reporter of
CVE-2012-3488, and Noah Misch as the original reporter of CVE-2012-3489.

These updated packages upgrade PostgreSQL to version 8.4.13. Refer to the
PostgreSQL Release Notes for a list of changes:

http://www.postgresql.org/docs/8.4/static/release-8-4-13.html

If the postgresql service is running, it will be automatically restarted
after installing this update.

SL5
   x86_64
     postgresql84-8.4.13-1.el5_8.x86_64.rpm
     postgresql84-contrib-8.4.13-1.el5_8.x86_64.rpm
     postgresql84-docs-8.4.13-1.el5_8.x86_64.rpm
     postgresql84-libs-8.4.13-1.el5_8.i386.rpm
     postgresql84-libs-8.4.13-1.el5_8.x86_64.rpm
     postgresql84-python-8.4.13-1.el5_8.x86_64.rpm
     postgresql84-tcl-8.4.13-1.el5_8.x86_64.rpm
     postgresql84-devel-8.4.13-1.el5_8.i386.rpm
     postgresql84-devel-8.4.13-1.el5_8.x86_64.rpm
     postgresql84-plperl-8.4.13-1.el5_8.x86_64.rpm
     postgresql84-plpython-8.4.13-1.el5_8.x86_64.rpm
     postgresql84-pltcl-8.4.13-1.el5_8.x86_64.rpm
     postgresql84-server-8.4.13-1.el5_8.x86_64.rpm
     postgresql84-test-8.4.13-1.el5_8.x86_64.rpm
   i386
     postgresql84-8.4.13-1.el5_8.i386.rpm
     postgresql84-contrib-8.4.13-1.el5_8.i386.rpm
     postgresql84-docs-8.4.13-1.el5_8.i386.rpm
     postgresql84-libs-8.4.13-1.el5_8.i386.rpm
     postgresql84-python-8.4.13-1.el5_8.i386.rpm
     postgresql84-tcl-8.4.13-1.el5_8.i386.rpm
     postgresql84-devel-8.4.13-1.el5_8.i386.rpm
     postgresql84-plperl-8.4.13-1.el5_8.i386.rpm
     postgresql84-plpython-8.4.13-1.el5_8.i386.rpm
     postgresql84-pltcl-8.4.13-1.el5_8.i386.rpm
     postgresql84-server-8.4.13-1.el5_8.i386.rpm
     postgresql84-test-8.4.13-1.el5_8.i386.rpm

SL6
   x86_64
     postgresql-libs-8.4.13-1.el6_3.i686.rpm
     postgresql-libs-8.4.13-1.el6_3.x86_64.rpm
     postgresql-8.4.13-1.el6_3.i686.rpm
     postgresql-8.4.13-1.el6_3.x86_64.rpm
     postgresql-contrib-8.4.13-1.el6_3.x86_64.rpm
     postgresql-devel-8.4.13-1.el6_3.i686.rpm
     postgresql-devel-8.4.13-1.el6_3.x86_64.rpm
     postgresql-docs-8.4.13-1.el6_3.x86_64.rpm
     postgresql-plperl-8.4.13-1.el6_3.x86_64.rpm
     postgresql-plpython-8.4.13-1.el6_3.x86_64.rpm
     postgresql-pltcl-8.4.13-1.el6_3.x86_64.rpm
     postgresql-server-8.4.13-1.el6_3.x86_64.rpm
     postgresql-test-8.4.13-1.el6_3.x86_64.rpm
   i386
     postgresql-libs-8.4.13-1.el6_3.i686.rpm
     postgresql-8.4.13-1.el6_3.i686.rpm
     postgresql-contrib-8.4.13-1.el6_3.i686.rpm
     postgresql-devel-8.4.13-1.el6_3.i686.rpm
     postgresql-docs-8.4.13-1.el6_3.i686.rpm
     postgresql-plperl-8.4.13-1.el6_3.i686.rpm
     postgresql-plpython-8.4.13-1.el6_3.i686.rpm
     postgresql-pltcl-8.4.13-1.el6_3.i686.rpm
     postgresql-server-8.4.13-1.el6_3.i686.rpm
     postgresql-test-8.4.13-1.el6_3.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2