Synopsis:	Moderate: postgresql security update
Issue date:	2011-02-03
CVE Names:	CVE-2010-4015

A stack-based buffer overflow flaw was found in the way PostgreSQL
processed certain tokens from an SQL query when the intarray module was
enabled on a particular database. An authenticated database user running 
a specially-crafted SQL query could use this flaw to cause a temporary 
denial of service (postgres daemon crash) or, potentially, execute 
arbitrary code with the privileges of the database server. (CVE-2010-4015)


For Scientific Linux 4, the updated postgresql packages contain a
backported patch for this issue; there are no other changes.

For Scientific Linux 5, the updated postgresql packages upgrade 
PostgreSQL to version 8.1.23, and contain a backported patch for this
issue. Refer to the PostgreSQL Release Notes for a full list of changes:

http://www.postgresql.org/docs/8.1/static/release.html

If the postgresql service is running, it will be automatically restarted 
after installing this update.


SL 4.x

      SRPMS:
postgresql-7.4.30-1.el4_8.2.src.rpm
      i386:
postgresql-7.4.30-1.el4_8.2.i386.rpm
postgresql-contrib-7.4.30-1.el4_8.2.i386.rpm
postgresql-devel-7.4.30-1.el4_8.2.i386.rpm
postgresql-docs-7.4.30-1.el4_8.2.i386.rpm
postgresql-jdbc-7.4.30-1.el4_8.2.i386.rpm
postgresql-libs-7.4.30-1.el4_8.2.i386.rpm
postgresql-pl-7.4.30-1.el4_8.2.i386.rpm
postgresql-python-7.4.30-1.el4_8.2.i386.rpm
postgresql-server-7.4.30-1.el4_8.2.i386.rpm
postgresql-tcl-7.4.30-1.el4_8.2.i386.rpm
postgresql-test-7.4.30-1.el4_8.2.i386.rpm
      x86_64:
postgresql-7.4.30-1.el4_8.2.x86_64.rpm
postgresql-contrib-7.4.30-1.el4_8.2.x86_64.rpm
postgresql-devel-7.4.30-1.el4_8.2.x86_64.rpm
postgresql-docs-7.4.30-1.el4_8.2.x86_64.rpm
postgresql-jdbc-7.4.30-1.el4_8.2.x86_64.rpm
postgresql-libs-7.4.30-1.el4_8.2.i386.rpm
postgresql-libs-7.4.30-1.el4_8.2.x86_64.rpm
postgresql-pl-7.4.30-1.el4_8.2.x86_64.rpm
postgresql-python-7.4.30-1.el4_8.2.x86_64.rpm
postgresql-server-7.4.30-1.el4_8.2.x86_64.rpm
postgresql-tcl-7.4.30-1.el4_8.2.x86_64.rpm
postgresql-test-7.4.30-1.el4_8.2.x86_64.rpm

SL 5.x

      SRPMS:
postgresql-8.1.23-1.el5_6.1.src.rpm
      i386:
postgresql-8.1.23-1.el5_6.1.i386.rpm
postgresql-contrib-8.1.23-1.el5_6.1.i386.rpm
postgresql-devel-8.1.23-1.el5_6.1.i386.rpm
postgresql-docs-8.1.23-1.el5_6.1.i386.rpm
postgresql-libs-8.1.23-1.el5_6.1.i386.rpm
postgresql-pl-8.1.23-1.el5_6.1.i386.rpm
postgresql-python-8.1.23-1.el5_6.1.i386.rpm
postgresql-server-8.1.23-1.el5_6.1.i386.rpm
postgresql-tcl-8.1.23-1.el5_6.1.i386.rpm
postgresql-test-8.1.23-1.el5_6.1.i386.rpm

      x86_64:
postgresql-8.1.23-1.el5_6.1.x86_64.rpm
postgresql-contrib-8.1.23-1.el5_6.1.x86_64.rpm
postgresql-devel-8.1.23-1.el5_6.1.i386.rpm
postgresql-devel-8.1.23-1.el5_6.1.x86_64.rpm
postgresql-docs-8.1.23-1.el5_6.1.x86_64.rpm
postgresql-libs-8.1.23-1.el5_6.1.i386.rpm
postgresql-libs-8.1.23-1.el5_6.1.x86_64.rpm
postgresql-pl-8.1.23-1.el5_6.1.x86_64.rpm
postgresql-python-8.1.23-1.el5_6.1.x86_64.rpm
postgresql-server-8.1.23-1.el5_6.1.x86_64.rpm
postgresql-tcl-8.1.23-1.el5_6.1.x86_64.rpm
postgresql-test-8.1.23-1.el5_6.1.x86_64.rpm

-Connie Sieh
-Troy Dawson