Bug 16027 - postgresql new security issues fixed upstream in 9.4.2, 9.3.7, 9.2.11, 9.1.16, and 9.0.20 (CVE-2015-316[5-7])
Summary: postgresql new security issues fixed upstream in 9.4.2, 9.3.7, 9.2.11, 9.1.16...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 4
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/645926/
Whiteboard: has_procedure MGA4-32-OK MGA4-64-OK a...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2015-05-23 12:46 CEST by David Walser
Modified: 2015-07-01 14:41 CEST (History)
4 users (show)

See Also:
Source RPM: postgresql
CVE:
Status comment:


Attachments

Description David Walser 2015-05-23 12:46:18 CEST
Upstream has announced new versions on May 22:
http://www.postgresql.org/about/news/1587/

A data corruption bug and three security issues have been fixed.

Reproducible: 

Steps to Reproduce:
David Walser 2015-05-23 12:46:38 CEST

CC: (none) => oe
Whiteboard: (none) => MGA5TOO, MGA4TOO

Comment 1 David Walser 2015-05-26 21:01:11 CEST
Ubuntu has issued an advisory for this on May 25:
http://www.ubuntu.com/usn/usn-2621-1/

URL: (none) => http://lwn.net/Vulnerabilities/645926/

Comment 2 David Walser 2015-06-04 20:34:11 CEST
PostgreSQL 9.4.3, 9.3.8, 9.2.12, 9.1.17 & 9.0.21 have been released, fixing a regression from the previous update:
http://www.postgresql.org/about/news/1590/
Comment 3 David Walser 2015-06-13 19:50:13 CEST
PostgreSQL 9.4.4, 9.3.9, 9.2.13, 9.1.18 & 9.0.22 have been released, fixing another regressions:
http://www.postgresql.org/about/news/1592/
Comment 4 David Walser 2015-06-13 21:15:40 CEST
Updates for 9.3 and 9.4 checked into Cauldron SVN.  Freeze push requested.

Summary: postgresql new security issues fixed upstream in 9.4.2, 9.3.7, 9.2.11, 9.1.16, and 9.0.20 => postgresql new security issues fixed upstream in 9.4.2, 9.3.7, 9.2.11, 9.1.16, and 9.0.20 (CVE-2015-316[5-7])

Comment 5 David Walser 2015-06-13 22:37:18 CEST
Updated packages uploaded for Mageia 4 and Cauldron.

Advisory:
========================

Updated postgresql packages fix security vulnerabilities:

Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16,
9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote
attackers to cause a denial of service (crash) by closing an SSL session at a
time when the authentication timeout will expire during the session shutdown
sequence (CVE-2015-3165).

The replacement implementation of snprintf() failed to check for errors
reported by the underlying system library calls; the main case that might be
missed is out-of-memory situations. In the worst case this might lead to
information exposure (CVE-2015-3166).

In contrib/pgcrypto, some cases of decryption with an incorrect key could
report other error message texts, possibly leading to a side-channel key
exposure (CVE-2015-3167).

The postgresql9.0, postgresql9.1, postgresql9.2, and postgresql9.3 packages
have been updated to versions 9.0.22, 9.1.18, 9.2.13, and 9.3.9, respectively,
fixing these issues, as well as some data corruption issues.  See the upstream
release notes for more details.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3165
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3166
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3167
http://www.postgresql.org/about/news/1587/
http://www.postgresql.org/about/news/1590/
http://www.postgresql.org/about/news/1592/
https://www.debian.org/security/2015/dsa-3269
========================

Updated packages in core/updates_testing:
========================
postgresql9.0-9.0.22-1.mga4
libpq9.0_5.3-9.0.22-1.mga4
libecpg9.0_6-9.0.22-1.mga4
postgresql9.0-server-9.0.22-1.mga4
postgresql9.0-docs-9.0.22-1.mga4
postgresql9.0-contrib-9.0.22-1.mga4
postgresql9.0-devel-9.0.22-1.mga4
postgresql9.0-pl-9.0.22-1.mga4
postgresql9.0-plpython-9.0.22-1.mga4
postgresql9.0-plperl-9.0.22-1.mga4
postgresql9.0-pltcl-9.0.22-1.mga4
postgresql9.0-plpgsql-9.0.22-1.mga4
postgresql9.1-9.1.18-1.mga4
libpq9.1_5.4-9.1.18-1.mga4
libecpg9.1_6-9.1.18-1.mga4
postgresql9.1-server-9.1.18-1.mga4
postgresql9.1-docs-9.1.18-1.mga4
postgresql9.1-contrib-9.1.18-1.mga4
postgresql9.1-devel-9.1.18-1.mga4
postgresql9.1-pl-9.1.18-1.mga4
postgresql9.1-plpython-9.1.18-1.mga4
postgresql9.1-plperl-9.1.18-1.mga4
postgresql9.1-pltcl-9.1.18-1.mga4
postgresql9.1-plpgsql-9.1.18-1.mga4
postgresql9.2-9.2.13-1.mga4
libpq9.2_5.5-9.2.13-1.mga4
libecpg9.2_6-9.2.13-1.mga4
postgresql9.2-server-9.2.13-1.mga4
postgresql9.2-docs-9.2.13-1.mga4
postgresql9.2-contrib-9.2.13-1.mga4
postgresql9.2-devel-9.2.13-1.mga4
postgresql9.2-pl-9.2.13-1.mga4
postgresql9.2-plpython-9.2.13-1.mga4
postgresql9.2-plperl-9.2.13-1.mga4
postgresql9.2-pltcl-9.2.13-1.mga4
postgresql9.2-plpgsql-9.2.13-1.mga4
postgresql9.3-9.3.9-1.mga4
libpq9.3_5-9.3.9-1.mga4
libecpg9.3_6-9.3.9-1.mga4
postgresql9.3-server-9.3.9-1.mga4
postgresql9.3-docs-9.3.9-1.mga4
postgresql9.3-contrib-9.3.9-1.mga4
postgresql9.3-devel-9.3.9-1.mga4
postgresql9.3-pl-9.3.9-1.mga4
postgresql9.3-plpython-9.3.9-1.mga4
postgresql9.3-plperl-9.3.9-1.mga4
postgresql9.3-pltcl-9.3.9-1.mga4
postgresql9.3-plpgsql-9.3.9-1.mga4

from SRPMS:
postgresql9.0-9.0.22-1.mga4.src.rpm
postgresql9.1-9.1.18-1.mga4.src.rpm
postgresql9.2-9.2.13-1.mga4.src.rpm
postgresql9.3-9.3.9-1.mga4.src.rpm

Version: Cauldron => 4
Assignee: cjw => qa-bugs
Whiteboard: MGA5TOO, MGA4TOO => (none)

Comment 6 Herman Viaene 2015-06-19 11:23:11 CEST
MGA4-64 on HP Probook6555b KDE
Installing the 9.3 version (did not have any version installed previously): no installation issues.
Can start postgres at the CLI, and I am able to access it via pgAdminIII.
Is that sufficient as test?

CC: (none) => herman.viaene

Comment 7 David Walser 2015-06-19 12:29:25 CEST
I think so.  Just make sure to test 9.2, 9.1, and 9.0 as well.  Thanks!
Comment 8 Herman Viaene 2015-06-22 10:41:17 CEST
Same as Comment 6 for 9.2: test OK
Comment 9 Herman Viaene 2015-06-22 11:02:23 CEST
And idem fo versions 9.0 and 9.1

Whiteboard: (none) => has_procedure MGA4-64-OK

Comment 10 Herman Viaene 2015-06-22 17:20:49 CEST
MGA4-32 on AcerD620 Xfce.
No installation issues.
All versions tested as above and all OK.

Whiteboard: has_procedure MGA4-64-OK => has_procedure MGA4-32-OK MGA4-64-OK

Dave Hodgins 2015-07-01 01:56:00 CEST

Keywords: (none) => validated_update
Whiteboard: has_procedure MGA4-32-OK MGA4-64-OK => has_procedure MGA4-32-OK MGA4-64-OK advisory
CC: (none) => davidwhodgins, sysadmin-bugs

Comment 11 Dave Hodgins 2015-07-01 02:17:39 CEST
Advisory committed to svn.

Someone from the sysadmin team please push 16027 to updates for Mageia 4.
Comment 12 Mageia Robot 2015-07-01 14:41:07 CEST
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2015-0250.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.