| Summary: | postgresql new security issues CVE-2017-12172 and CVE-2017-1509[89] | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | cjw, guillomovitch, herman.viaene, lewyssmith, sysadmin-bugs |
| Version: | 6 | Keywords: | advisory, has_procedure, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA5TOO MGA5-32-OK MGA5-64-OK MGA6-64-OK | ||
| Source RPM: | postgresql9.3, postgresql9.4, postgresql9.6 | CVE: | |
| Status comment: | |||
|
Description
David Walser
2017-11-10 01:58:12 CET
They don't build in Cauldron due to breakage in the osx command (opensp package). CC'ing Guillaume who changed opensp in Cauldron. CC:
(none) =>
cjw, guillomovitch Debian has issued advisories for this on November 9: https://www.debian.org/security/2017/dsa-4028 https://www.debian.org/security/2017/dsa-4027 They also had this one. I don't think we have these commands packaged, but hopefully Christiaan can confirm it's not relevant for us: https://www.debian.org/security/2017/dsa-4029 (In reply to David Walser from comment #2) > They also had this one. I don't think we have these commands packaged, but > hopefully Christiaan can confirm it's not relevant for us: > https://www.debian.org/security/2017/dsa-4029 Also seen here with another CVE: https://usn.ubuntu.com/usn/usn-3476-1/ but it does appear to be a Debian-specific thing. MGA5-32 on Asus A6000VM Xfce Installed 9.4.15-1 over existing 9.4.13-1 Existing test database intact and working. Could create new database and new table in it. CC:
(none) =>
herman.viaene The docbook nightmare never ends... I just fixed the docbook-dtds package, you should be able to rebuild postgresql in cauldron now.
Lewis Smith
2017-11-19 11:42:02 CET
Keywords:
(none) =>
advisory MGA5-64 on Lenovo B50 KDE No installation issues Using phppgadmin first threw "Login disallowed for security reasons." Setting $conf['extra_login_security'] = false; in /etc/phppgadmin/conf.inc.php solved this. Postgres was installed before, so I could use the existing database. Then I could create a table in the public schema, create a new schema anda table in that one. All seems OK. Whiteboard:
MGA5TOO MGA5-32-OK =>
MGA5TOO MGA5-32-OK MGA5-64-OK Testing M6/64 AFTER update for: postgresql9.6-plpgsql-9.6.6-1.mga6 postgresql9.6-9.6.6-1.mga6 postgresql9.6-server-9.6.6-1.mga6 lib64pq5-9.6.6-1.mga6 To drive this, I used: pgAdmin3, MediaWiki, Bugzilla pgAdmin3: I could create a database, add tables, alter them, delete them; same for columns. Unable to add any data because I could *not* find how to define table primary keys with it - a prerequisite. MediaWiki, Bugzilla: Added and edited entitites; all seemed OK. I am OKing & validating this because Herman covered M5 and Postgres 9.4, here M6 and Postgres 9.6. If anyone wants also M5/Postgres 9.3 and M6/Postgres 9.4, please shout & unvalidate. CC:
(none) =>
lewyssmith, sysadmin-bugs An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2017-0428.html Resolution:
(none) =>
FIXED |