[<prev] [next>] [day] [month] [year] [list]
Message-Id: <E1aUbwh-0007A5-5J@master.debian.org>
Date: Sat, 13 Feb 2016 15:17:15 +0000
From: Salvatore Bonaccorso <carnil@...ian.org>
To: bugtraq@...urityfocus.com
Subject: [SECURITY] [DSA 3476-1] postgresql-9.4 security update
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-3476-1 security@...ian.org
https://www.debian.org/security/ Salvatore Bonaccorso
February 13, 2016 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : postgresql-9.4
CVE ID : CVE-2016-0766 CVE-2016-0773
Several vulnerabilities have been found in PostgreSQL-9.4, a SQL
database system.
CVE-2016-0766
A privilege escalation vulnerability for users of PL/Java was
discovered. Certain custom configuration settings (GUCs) for PL/Java
will now be modifiable only by the database superuser to mitigate
this issue.
CVE-2016-0773
Tom Lane and Greg Stark discovered a flaw in the way PostgreSQL
processes specially crafted regular expressions. Very large
character ranges in bracket expressions could cause infinite
loops or memory overwrites. A remote attacker can exploit this
flaw to cause a denial of service or, potentially, to execute
arbitrary code.
For the stable distribution (jessie), these problems have been fixed in
version 9.4.6-0+deb8u1.
We recommend that you upgrade your postgresql-9.4 packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@...ts.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJWv0jBAAoJEAVMuPMTQ89EzvwP/jkX+nozpq+265YjViOL6aMa
G5Ldnt78HV7ls2ntbelyVg6lSgNysvjdbyWgT/OCB0F11FTsj4OR0udqLnZzFA7k
JEZnQu3AgIObXJYbjZDwlKS9JSELmz8spjGrPAlGwSdzcr9aXlOhLvagHcwJeZxU
mONY+oxahNxRUOSfonsM3l+YSK1XAoJLTFhl91Au0Sn+L9+kYB3ykOCiSW/H9dEb
Po5dkyyEyNXqTx2XHquKidtst1zx3L/aiichCPcK3QIffs56em3asaPfooPP6nH0
4ybVwLzqOL7DBgpwxspSblhg0ITt2wngcwm1zTMl+mRv++bJkfu4iEMrHF/MMLn3
yqHBLMiu7WmiZVf7Hg3TTX2RnuAbT5cdJC/p2xV4/fuJ+zwvIrPW8AvwjI2FGRU+
sakQzNCe4Hbtx0zAB4DgHIefSbQddUmi47UU1JD8o0SQkNCwgMywMuqmFHi4x0ZO
DIEC3QE4azJNZ6I2hqzhPWChcODTWvpuYBLkH7BH8DuIDHLcwmO1nPKPB0t8ZBI1
Fm5BxEwH86XfOYp7vC5ZHK1i3kbYH4jmTRQYfcR8wwLvaTc7/ZQ86/dNEqDTpF8c
cxgiBEZLr6GYfOocR/YBR6qE2dHsS6iL1UpeDI+BashbUdd7HZHExvojk8x8B3Hy
D52qz20+Vw4WO4j8WRX/
=Svoo
-----END PGP SIGNATURE-----
Powered by blists - more mailing lists