Описание
Security update for postgresql91
This update provides PostgreSQL 9.1.18, which brings fixes for security issues and other enhancements.
The following vulnerabilities have been fixed:
For a comprehensive list of changes, please refer to http://www.postgresql.org/docs/9.1/static/release-9-1-18.html http://www.postgresql.org/docs/9.1/static/release-9-1-18.html .
This update also includes changes in PostgreSQL's packaging to prepare for the migration to the new major version 9.4. (FATE#316970, bsc#907651)
Security Issues:
Список пакетов
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP3-TERADATA
SUSE Linux Enterprise Server for SAP Applications 11 SP3
SUSE Linux Enterprise Software Development Kit 11 SP3
SUSE Manager 2.1
Ссылки
- Link for SUSE-SU-2015:1091-1
- E-Mail link for SUSE-SU-2015:1091-1
- SUSE Security Ratings
- SUSE Bug 907651
- SUSE Bug 931972
- SUSE Bug 931973
- SUSE Bug 931974
- SUSE Bug 932040
- SUSE CVE CVE-2015-3165 page
- SUSE CVE CVE-2015-3166 page
- SUSE CVE CVE-2015-3167 page
Описание
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.
Затронутые продукты
Ссылки
- CVE-2015-3165
- SUSE Bug 931972
- SUSE Bug 931973
- SUSE Bug 931974
- SUSE Bug 932040
Описание
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via unknown vectors, as demonstrated by an out-of-memory error.
Затронутые продукты
Ссылки
- CVE-2015-3166
- SUSE Bug 931972
- SUSE Bug 931973
- SUSE Bug 931974
- SUSE Bug 932040
Описание
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
Затронутые продукты
Ссылки
- CVE-2015-3167
- SUSE Bug 931972
- SUSE Bug 931973
- SUSE Bug 931974
- SUSE Bug 932040