Bug 6334 - Updates postgresql packages to fix multiple security vulnerabilities
Summary: Updates postgresql packages to fix multiple security vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 2
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL: http://www.postgresql.org/support/sec...
Whiteboard: mga1-i586-OK, mga2-i586-OK, mga1-64-O...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2012-06-05 06:19 CEST by Funda Wang
Modified: 2012-06-10 16:57 CEST (History)
3 users (show)

See Also:
Source RPM: postgresql[8.4,9.0,9.1]
CVE:
Status comment:


Attachments

Description Funda Wang 2012-06-05 06:19:30 CEST
The postgresql packages have been updated to latest versions of current series, to fix multiple security vulnerabilities:

CVE-2012-2143: Passwords containing the byte 0x80 passed to the crypt() function in pgcrypto are incorrectly truncated if DES encryption was used.

CVE-2012-2655: SECURITY DEFINER and SET attributes on procedural call handlers are not ignored and can be used to crash the server.

List of packages:
Mageia 1:
postgresql8.4-8.4.12-1.mga1
postgresql9.0-9.0.8-1.mga1

Mageia 2:
postgresql8.4-8.4.12-1.mga2
postgresql9.0-9.0.8-1.mga2
postgresql9.1-9.1.4-1.mga2
Comment 1 Dave Hodgins 2012-06-06 03:07:42 CEST
I couldn't find any poc for the bugs, so just testing that
the servers work.

Currently testing postgresql9.0 on i586 Mageia 1.

CC: (none) => davidwhodgins

Comment 2 Dave Hodgins 2012-06-06 03:57:11 CEST
Testing complete on i586/Mageia 1 for the srpm
postgresql9.0-9.0.8-1.mga1.src.rpm

I used webmin to run the sql from
http://pgfoundry.org/frs/download.php/527/world-1.0.tar.gz
to create the tables, and view the data.

I'll now be testing postgresql8.4 on Mageia 1 i586.
Comment 3 Dave Hodgins 2012-06-06 04:21:34 CEST
Testing complete on i586/Mageia 1 for the srpm
postgresql8.4-8.4.12-1.mga1.src.rpm

After uninstalling postgresql9.0, deleting /var/lib/pgsql,
installing postgresql8.4-server, repeated the test using
the world sql, using webmin to run the sql from a file.

I'll test postgresql8.4 on Mageia 2 i586 shortly.
Comment 4 Dave Hodgins 2012-06-06 05:24:33 CEST
Testing complete on i586/Mageia 2 for the srpms
postgresql8.4-8.4.12-1.mga2
postgresql9.0-9.0.8-1.mga2
postgresql9.1-9.1.4-1.mga2

Note that in webmin, the postgresql shows up in the unused modules,
until the config for the module is edited, to correct the paths for
the various commands and the database directory.

Don't forget to delete /var/lib/pgsql before starting the next
version for testing.
Comment 5 claire robinson 2012-06-08 15:15:02 CEST
testing mga1 x86_64
claire robinson 2012-06-08 15:16:19 CEST

Whiteboard: (none) => mga1-i586-OK, mga2-i586-OK

Comment 6 claire robinson 2012-06-08 16:20:51 CEST
Testing complete mga1 x86_64 for srpms

postgresql8.4-8.4.12-1.mga1
postgresql9.0-9.0.8-1.mga1

Used webmin after altering a number of paths in the webmin postgresql module and the world.sql file same as Dave.

Verified by viewing tables and data afterwards.

Whiteboard: mga1-i586-OK, mga2-i586-OK => mga1-i586-OK, mga2-i586-OK, mga1-64-OK

Comment 7 claire robinson 2012-06-09 11:01:55 CEST
Testing complete mga2 x86_64

postgresql8.4-8.4.12-1.mga2
postgresql9.0-9.0.8-1.mga2
postgresql9.1-9.1.4-1.mga2


Validating

This contains updates for both mga1 and mga2 which should be pushed at the same time.

Please see comment 0 for advisory and srpms.

Could sysadmin please push from core/updates_testing to core/updates

Thanks!

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs
Whiteboard: mga1-i586-OK, mga2-i586-OK, mga1-64-OK => mga1-i586-OK, mga2-i586-OK, mga1-64-OK, mga2-64-OK

Comment 8 Thomas Backlund 2012-06-10 16:57:42 CEST
Update pushed:
https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0113

Status: NEW => RESOLVED
CC: (none) => tmb
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.