Synopsis:          Moderate: postgresql security update
Advisory ID:       SLSA-2017:2728-1
Issue Date:        2017-09-14
CVE Numbers:       CVE-2017-7546
                   CVE-2017-7547
--

The following packages have been upgraded to a later upstream version:
postgresql (9.2.23).

Security Fix(es):

* It was found that authenticating to a PostgreSQL database account with
an empty password was possible despite libpq's refusal to send an empty
password. A remote attacker could potentially use this flaw to gain access
to database accounts with empty passwords. (CVE-2017-7546)

* An authorization flaw was found in the way PostgreSQL handled access to
the pg_user_mappings view on foreign servers. A remote, authenticated
attacker could potentially use this flaw to retrieve passwords from the
user mappings defined by the foreign server owners without actually having
the privileges to do so. (CVE-2017-7547)
--

SL7
  x86_64
    postgresql-debuginfo-9.2.23-1.el7_4.i686.rpm
    postgresql-debuginfo-9.2.23-1.el7_4.x86_64.rpm
    postgresql-libs-9.2.23-1.el7_4.i686.rpm
    postgresql-libs-9.2.23-1.el7_4.x86_64.rpm
    postgresql-9.2.23-1.el7_4.i686.rpm
    postgresql-9.2.23-1.el7_4.x86_64.rpm
    postgresql-contrib-9.2.23-1.el7_4.x86_64.rpm
    postgresql-devel-9.2.23-1.el7_4.i686.rpm
    postgresql-devel-9.2.23-1.el7_4.x86_64.rpm
    postgresql-docs-9.2.23-1.el7_4.x86_64.rpm
    postgresql-plperl-9.2.23-1.el7_4.x86_64.rpm
    postgresql-plpython-9.2.23-1.el7_4.x86_64.rpm
    postgresql-pltcl-9.2.23-1.el7_4.x86_64.rpm
    postgresql-server-9.2.23-1.el7_4.x86_64.rpm
    postgresql-static-9.2.23-1.el7_4.i686.rpm
    postgresql-static-9.2.23-1.el7_4.x86_64.rpm
    postgresql-test-9.2.23-1.el7_4.x86_64.rpm
    postgresql-upgrade-9.2.23-1.el7_4.x86_64.rpm

- Scientific Linux Development Team