From Mageia wiki
Jump to: navigation, search

MGASA-2013-0049

Date: February 13th, 2013
Affected releases: 2
Media: Core


Description:
Updated postgresql packages fix security vulnerability:

An array index error, leading to out of heap-based buffer bounds read flaw
was found in the way PostgreSQL, an advanced Object-Relational database
management system (DBMS), performed retrieval of textual form of error
message representation when processing certain enumeration types. An
unprivileged database user could issue a specially-crafted SQL query that,
when processed by the server component of the PostgreSQL service, would
lead to denial of service (daemon crash) or disclosure (of certain
portions of) server memory (CVE-2013-0255).


Updated Packages:
i586:
libecpg8.4_6-8.4.16-1.mga2.i586.rpm
libpq8.4_5-8.4.16-1.mga2.i586.rpm
postgresql8.4-8.4.16-1.mga2.i586.rpm
postgresql8.4-contrib-8.4.16-1.mga2.i586.rpm
postgresql8.4-devel-8.4.16-1.mga2.i586.rpm
postgresql8.4-docs-8.4.16-1.mga2.i586.rpm
postgresql8.4-pl-8.4.16-1.mga2.i586.rpm
postgresql8.4-plperl-8.4.16-1.mga2.i586.rpm
postgresql8.4-plpgsql-8.4.16-1.mga2.i586.rpm
postgresql8.4-plpython-8.4.16-1.mga2.i586.rpm
postgresql8.4-pltcl-8.4.16-1.mga2.i586.rpm
postgresql8.4-server-8.4.16-1.mga2.i586.rpm
postgresql8.4-debug-8.4.16-1.mga2.i586.rpm

libecpg9.0_6-9.0.12-1.mga2.i586.rpm
libpq9.0_5-9.0.12-1.mga2.i586.rpm
postgresql9.0-9.0.12-1.mga2.i586.rpm
postgresql9.0-contrib-9.0.12-1.mga2.i586.rpm
postgresql9.0-devel-9.0.12-1.mga2.i586.rpm
postgresql9.0-docs-9.0.12-1.mga2.i586.rpm
postgresql9.0-pl-9.0.12-1.mga2.i586.rpm
postgresql9.0-plperl-9.0.12-1.mga2.i586.rpm
postgresql9.0-plpgsql-9.0.12-1.mga2.i586.rpm
postgresql9.0-plpython-9.0.12-1.mga2.i586.rpm
postgresql9.0-pltcl-9.0.12-1.mga2.i586.rpm
postgresql9.0-server-9.0.12-1.mga2.i586.rpm
postgresql9.0-debug-9.0.12-1.mga2.i586.rpm

libecpg9.1_6-9.1.8-1.mga2.i586.rpm
libpq9.1_5-9.1.8-1.mga2.i586.rpm
postgresql9.1-9.1.8-1.mga2.i586.rpm
postgresql9.1-contrib-9.1.8-1.mga2.i586.rpm
postgresql9.1-devel-9.1.8-1.mga2.i586.rpm
postgresql9.1-docs-9.1.8-1.mga2.i586.rpm
postgresql9.1-pl-9.1.8-1.mga2.i586.rpm
postgresql9.1-plperl-9.1.8-1.mga2.i586.rpm
postgresql9.1-plpgsql-9.1.8-1.mga2.i586.rpm
postgresql9.1-plpython-9.1.8-1.mga2.i586.rpm
postgresql9.1-pltcl-9.1.8-1.mga2.i586.rpm
postgresql9.1-server-9.1.8-1.mga2.i586.rpm
postgresql9.1-debug-9.1.8-1.mga2.i586.rpm

x86_64:
lib64ecpg8.4_6-8.4.16-1.mga2.x86_64.rpm
lib64pq8.4_5-8.4.16-1.mga2.x86_64.rpm
postgresql8.4-8.4.16-1.mga2.x86_64.rpm
postgresql8.4-contrib-8.4.16-1.mga2.x86_64.rpm
postgresql8.4-devel-8.4.16-1.mga2.x86_64.rpm
postgresql8.4-docs-8.4.16-1.mga2.x86_64.rpm
postgresql8.4-pl-8.4.16-1.mga2.x86_64.rpm
postgresql8.4-plperl-8.4.16-1.mga2.x86_64.rpm
postgresql8.4-plpgsql-8.4.16-1.mga2.x86_64.rpm
postgresql8.4-plpython-8.4.16-1.mga2.x86_64.rpm
postgresql8.4-pltcl-8.4.16-1.mga2.x86_64.rpm
postgresql8.4-server-8.4.16-1.mga2.x86_64.rpm
postgresql8.4-debug-8.4.16-1.mga2.x86_64.rpm

lib64ecpg9.0_6-9.0.12-1.mga2.x86_64.rpm
lib64pq9.0_5-9.0.12-1.mga2.x86_64.rpm
postgresql9.0-9.0.12-1.mga2.x86_64.rpm
postgresql9.0-contrib-9.0.12-1.mga2.x86_64.rpm
postgresql9.0-devel-9.0.12-1.mga2.x86_64.rpm
postgresql9.0-docs-9.0.12-1.mga2.x86_64.rpm
postgresql9.0-pl-9.0.12-1.mga2.x86_64.rpm
postgresql9.0-plperl-9.0.12-1.mga2.x86_64.rpm
postgresql9.0-plpgsql-9.0.12-1.mga2.x86_64.rpm
postgresql9.0-plpython-9.0.12-1.mga2.x86_64.rpm
postgresql9.0-pltcl-9.0.12-1.mga2.x86_64.rpm
postgresql9.0-server-9.0.12-1.mga2.x86_64.rpm
postgresql9.0-debug-9.0.12-1.mga2.x86_64.rpm

lib64ecpg9.1_6-9.1.8-1.mga2.x86_64.rpm
lib64pq9.1_5-9.1.8-1.mga2.x86_64.rpm
postgresql9.1-9.1.8-1.mga2.x86_64.rpm
postgresql9.1-contrib-9.1.8-1.mga2.x86_64.rpm
postgresql9.1-devel-9.1.8-1.mga2.x86_64.rpm
postgresql9.1-docs-9.1.8-1.mga2.x86_64.rpm
postgresql9.1-pl-9.1.8-1.mga2.x86_64.rpm
postgresql9.1-plperl-9.1.8-1.mga2.x86_64.rpm
postgresql9.1-plpgsql-9.1.8-1.mga2.x86_64.rpm
postgresql9.1-plpython-9.1.8-1.mga2.x86_64.rpm
postgresql9.1-pltcl-9.1.8-1.mga2.x86_64.rpm
postgresql9.1-server-9.1.8-1.mga2.x86_64.rpm
postgresql9.1-debug-9.1.8-1.mga2.x86_64.rpm

SRPMS:
postgresql8.4-8.4.16-1.mga2.src.rpm
postgresql9.0-9.0.12-1.mga2.src.rpm
postgresql9.1-9.1.8-1.mga2.src.rpm


References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0255
http://www.postgresql.org/about/news/1446/
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098586.html
https://bugs.mageia.org/show_bug.cgi?id=8997