Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2017-2860

Опубликовано: 05 окт. 2017
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2017-2860: postgresql security update (MODERATE)

[8.4.20-8]

  • backport fix for CVE-2017-7546 (rhbz#1484677)

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

postgresql

8.4.20-8.el6_9

postgresql-contrib

8.4.20-8.el6_9

postgresql-devel

8.4.20-8.el6_9

postgresql-docs

8.4.20-8.el6_9

postgresql-libs

8.4.20-8.el6_9

postgresql-plperl

8.4.20-8.el6_9

postgresql-plpython

8.4.20-8.el6_9

postgresql-pltcl

8.4.20-8.el6_9

postgresql-server

8.4.20-8.el6_9

postgresql-test

8.4.20-8.el6_9

Oracle Linux i686

postgresql

8.4.20-8.el6_9

postgresql-contrib

8.4.20-8.el6_9

postgresql-devel

8.4.20-8.el6_9

postgresql-docs

8.4.20-8.el6_9

postgresql-libs

8.4.20-8.el6_9

postgresql-plperl

8.4.20-8.el6_9

postgresql-plpython

8.4.20-8.el6_9

postgresql-pltcl

8.4.20-8.el6_9

postgresql-server

8.4.20-8.el6_9

postgresql-test

8.4.20-8.el6_9

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.

CVSS3: 5.6
redhat
почти 8 лет назад

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.

CVSS3: 9.8
nvd
почти 8 лет назад

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.

CVSS3: 9.8
debian
почти 8 лет назад

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are ...

CVSS3: 9.8
github
около 3 лет назад

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.