Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2016:0482-1

Опубликовано: 16 фев. 2016
Источник: suse-cvrf

Описание

Security update for postgresql94

This update of postgresql94 to 9.4.5 fixes the following issues:

  • CVE-2015-5289: json or jsonb input values constructed from arbitrary user input could have crashed the PostgreSQL server and caused a denial of service (bsc#949670)
  • CVE-2015-5288: crypt() (pgCrypto extension) couldi potentially be exploited to read a few additional bytes of memory (bsc#949669)

Also contains all changes and bugfixes in the upstream 9.4.5 release: http://www.postgresql.org/docs/current/static/release-9-4-5.html

Список пакетов

SUSE Linux Enterprise Desktop 11 SP3
libecpg6-9.4.5-0.8.3
libpq5-9.4.5-0.8.3
libpq5-32bit-9.4.5-0.8.3
postgresql94-9.4.5-0.8.3
postgresql94-docs-9.4.5-0.8.3
SUSE Linux Enterprise Desktop 11 SP4
libecpg6-9.4.5-0.8.3
libpq5-9.4.5-0.8.3
libpq5-32bit-9.4.5-0.8.3
postgresql94-9.4.5-0.8.3
postgresql94-docs-9.4.5-0.8.3
SUSE Linux Enterprise Server 11 SP3
libecpg6-9.4.5-0.8.3
libpq5-9.4.5-0.8.3
libpq5-32bit-9.4.5-0.8.3
postgresql94-9.4.5-0.8.3
postgresql94-contrib-9.4.5-0.8.3
postgresql94-docs-9.4.5-0.8.3
postgresql94-server-9.4.5-0.8.3
SUSE Linux Enterprise Server 11 SP3-TERADATA
libecpg6-9.4.5-0.8.3
libpq5-9.4.5-0.8.3
libpq5-32bit-9.4.5-0.8.3
postgresql94-9.4.5-0.8.3
postgresql94-contrib-9.4.5-0.8.3
postgresql94-docs-9.4.5-0.8.3
postgresql94-server-9.4.5-0.8.3
SUSE Linux Enterprise Server 11 SP4
libecpg6-9.4.5-0.8.3
libpq5-9.4.5-0.8.3
libpq5-32bit-9.4.5-0.8.3
postgresql94-9.4.5-0.8.3
postgresql94-contrib-9.4.5-0.8.3
postgresql94-docs-9.4.5-0.8.3
postgresql94-server-9.4.5-0.8.3
SUSE Linux Enterprise Server for SAP Applications 11 SP3
libecpg6-9.4.5-0.8.3
libpq5-9.4.5-0.8.3
libpq5-32bit-9.4.5-0.8.3
postgresql94-9.4.5-0.8.3
postgresql94-contrib-9.4.5-0.8.3
postgresql94-docs-9.4.5-0.8.3
postgresql94-server-9.4.5-0.8.3
SUSE Linux Enterprise Server for SAP Applications 11 SP4
libecpg6-9.4.5-0.8.3
libpq5-9.4.5-0.8.3
libpq5-32bit-9.4.5-0.8.3
postgresql94-9.4.5-0.8.3
postgresql94-contrib-9.4.5-0.8.3
postgresql94-docs-9.4.5-0.8.3
postgresql94-server-9.4.5-0.8.3
SUSE Linux Enterprise Software Development Kit 11 SP3
postgresql94-devel-9.4.5-0.8.3
SUSE Linux Enterprise Software Development Kit 11 SP4
postgresql94-devel-9.4.5-0.8.3
SUSE Manager 2.1
postgresql94-pltcl-9.4.5-0.8.3

Описание

The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via a "too-short" salt.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libecpg6-9.4.5-0.8.3
SUSE Linux Enterprise Desktop 11 SP3:libpq5-32bit-9.4.5-0.8.3
SUSE Linux Enterprise Desktop 11 SP3:libpq5-9.4.5-0.8.3
SUSE Linux Enterprise Desktop 11 SP3:postgresql94-9.4.5-0.8.3

Ссылки

Описание

Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:libecpg6-9.4.5-0.8.3
SUSE Linux Enterprise Desktop 11 SP3:libpq5-32bit-9.4.5-0.8.3
SUSE Linux Enterprise Desktop 11 SP3:libpq5-9.4.5-0.8.3
SUSE Linux Enterprise Desktop 11 SP3:postgresql94-9.4.5-0.8.3

Ссылки
Уязвимость SUSE-SU-2016:0482-1