-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

            ESB-2004.0693 -- Debian Security Advisory DSA 577-1
             New postgresql packages fix symlink vulnerability
                              1 November 2004

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:                postgresql
Publisher:              Debian
Operating System:       Debian GNU/Linux 3.0
                        Linux variants
                        UNIX variants
Impact:                 Overwrite Arbitrary Files
Access:                 Existing Account
CVE Names:              CAN-2004-0977
Original Bulletin URL:  http://www.debian.org/security/2004/dsa-577

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - --------------------------------------------------------------------------
Debian Security Advisory DSA 577-1                     security@debian.org
http://www.debian.org/security/                             Martin Schulze
October 29th, 2004                      http://www.debian.org/security/faq
- - --------------------------------------------------------------------------

Package        : postgresql
Vulnerability  : local
Problem-Type   : insecure temporary file
Debian-specific: no
CVE ID         : CAN-2004-0977
Debian Bug     : 278336

Trustix Security Engineers identified insecure temporary file creation
in a script included in the postgresql suite, an object-relational SQL
database.  This could lead an attacker to trick a user to overwrite
arbitrary files he has write access to.

For the stable distribution (woody) this problem has been fixed in
version 7.2.1-2woody6.

For the unstable distribution (sid) this problem has been fixed in
version 7.4.6-1.

We recommend that you upgrade your postgresql packages.


Upgrade Instructions
- - --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.0 alias woody
- - --------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6.dsc
      Size/MD5 checksum:      966 ded5f8b8dc34a7e1916526cc4fd7dc5a
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6.diff.gz
      Size/MD5 checksum:   119740 deb2918afe376395a218ebb3af0a58f2
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1.orig.tar.gz
      Size/MD5 checksum:  9237680 d075e9c49135899645dff57bc58d6233

  Architecture independent components:

    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-doc_7.2.1-2woody6_all.deb
      Size/MD5 checksum:  2069286 761ab47664aa2091451117b36c1ed27a

  Alpha architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_alpha.deb
      Size/MD5 checksum:    34456 ca83cb3c6c50453ef1b9d985f381f94b
    http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_alpha.deb
      Size/MD5 checksum:    68434 a74ea2a89fd9204c15b5f69bc72b2c20
    http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_alpha.deb
      Size/MD5 checksum:    77692 3734b0f8deaa70a1d6767a3c64540ffd
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_alpha.deb
      Size/MD5 checksum:    67398 df0adaaa2e9515a022535630e9578b5b
    http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_alpha.deb
      Size/MD5 checksum:   290006 a34a7323c402b398ab69632f5ba1502c
    http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_alpha.deb
      Size/MD5 checksum:   425130 cff2adecf3350847358fcc73f342d7cb
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_alpha.deb
      Size/MD5 checksum:  1816990 e44d03b061447dd5c7f3a2398755d2d9
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_alpha.deb
      Size/MD5 checksum:   319618 60341c5a6e04bb7eb35d51e0b74438b8
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_alpha.deb
      Size/MD5 checksum:   387260 fca85d766f1b8a5b5bc36c65b7fd3ab0
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_alpha.deb
      Size/MD5 checksum:   540920 17ec27505d8780845b5ee8c46b508447
    http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_alpha.deb
      Size/MD5 checksum:    65062 71df8dfcc3bd1e01c61afef8d4f542a2

  ARM architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_arm.deb
      Size/MD5 checksum:    31544 dceca235c5f3761563c0496bbdf8081a
    http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_arm.deb
      Size/MD5 checksum:    64554 4685e3c5d18e05ee04aa9151f300f872
    http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_arm.deb
      Size/MD5 checksum:    65408 23267380f3ce726d12026622fd46ebb5
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_arm.deb
      Size/MD5 checksum:    57632 d6c511486fea0cc1a4279cd493836a4e
    http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_arm.deb
      Size/MD5 checksum:   233960 2e2521fa2f55ee1f30e2c588efe1a804
    http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_arm.deb
      Size/MD5 checksum:   425312 2e5cd171343b4d417d9f2f77e782fd2f
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_arm.deb
      Size/MD5 checksum:  1599900 dc382fb54b28a24bf1762cbc751a06c6
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_arm.deb
      Size/MD5 checksum:   285262 79cdad278b2469e6fa1e25449c5a076c
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_arm.deb
      Size/MD5 checksum:   340834 afa8b402818ce10a53d066716445bf5a
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_arm.deb
      Size/MD5 checksum:   510784 a858e4543816651ffff7368382a96a03
    http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_arm.deb
      Size/MD5 checksum:    62348 1fd432a9f33fabfdbc838e5bdec7e852

  Intel IA-32 architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_i386.deb
      Size/MD5 checksum:    30622 10c495dd0a58995507af82394fc7365e
    http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_i386.deb
      Size/MD5 checksum:    61308 d18dd3267716ed11c73fec4887a765d3
    http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_i386.deb
      Size/MD5 checksum:    65928 65fbeef01507d3da9ec33d841eb7c3f7
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_i386.deb
      Size/MD5 checksum:    54504 0d398d95a78ff34eed1af80cbb2bb1ac
    http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_i386.deb
      Size/MD5 checksum:   201794 e4e91e0d6d8fd7e97e66c2f7e113ace2
    http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_i386.deb
      Size/MD5 checksum:   426178 1ea1649f9652636f2542e3512f8dec4e
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_i386.deb
      Size/MD5 checksum:  1553990 43435859901064f480b7d4075806c318
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_i386.deb
      Size/MD5 checksum:   281148 8a7f14be36ffcc3680019d17922608c5
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_i386.deb
      Size/MD5 checksum:   328138 1d10d4b588aed5583446d33370f1f019
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_i386.deb
      Size/MD5 checksum:   497868 0fd18eb00f7af4abc562fd38faec2856
    http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_i386.deb
      Size/MD5 checksum:    61412 cf5ade712d103c69025f99aeedc02b4f

  Intel IA-64 architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_ia64.deb
      Size/MD5 checksum:    39306 a73ea2b597b6de6f2878f91ba8e18fca
    http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_ia64.deb
      Size/MD5 checksum:    77126 81e44e18cdde75e7d04a6c01c0e2395a
    http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_ia64.deb
      Size/MD5 checksum:    90492 4d9b0d1b078847a17e1105d7ece0c3e0
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_ia64.deb
      Size/MD5 checksum:    76956 d624178ecec2e6531cf11c76dc78370b
    http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_ia64.deb
      Size/MD5 checksum:   333058 e25e535d26f255ed495d66ac841be0ca
    http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_ia64.deb
      Size/MD5 checksum:   425110 b1be38e75fdc1113311c02d118f78111
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_ia64.deb
      Size/MD5 checksum:  2092336 21b06a586c19ef989d23966e72912bca
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_ia64.deb
      Size/MD5 checksum:   363328 23526f19fd6b98428e8b866e3f3cc51c
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_ia64.deb
      Size/MD5 checksum:   434586 f4cb0ed9128b3c6f35a65e9d22e4e17b
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_ia64.deb
      Size/MD5 checksum:   554970 045697f48231134d43952fbc1b3b62bf
    http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_ia64.deb
      Size/MD5 checksum:    70934 8c88392a94a96392fb3eb8af13367659

  HP Precision architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_hppa.deb
      Size/MD5 checksum:    33774 da8b09d3f1798b58d37ce986a68a6e45
    http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_hppa.deb
      Size/MD5 checksum:    70438 26007954e08b2dcfdf4f2b0e7e1de27f
    http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_hppa.deb
      Size/MD5 checksum:    76858 a1f52d8f0d8ea55a17a8951d7323cb9c
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_hppa.deb
      Size/MD5 checksum:    65592 dd7bcaa0de6e26be9ea5eb7abfaea1af
    http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_hppa.deb
      Size/MD5 checksum:   254558 362c909f6b97629b8812e7c458d5474b
    http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_hppa.deb
      Size/MD5 checksum:   425244 83b414358a936677436d8c5958dfabac
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_hppa.deb
      Size/MD5 checksum:  1826252 45e3822de40415bb5821d5f5ab651677
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_hppa.deb
      Size/MD5 checksum:   304558 ebb1cbe5d5d7efe1debbddce054c0612
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_hppa.deb
      Size/MD5 checksum:   371930 598b08442ac3f16fd33d5b6d280b7475
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_hppa.deb
      Size/MD5 checksum:   524078 39d6874bdeb06a2ce17a75f53669050a
    http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_hppa.deb
      Size/MD5 checksum:    66100 9eaa1e1cfc71d3b51f52061770485be2

  Motorola 680x0 architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_m68k.deb
      Size/MD5 checksum:    30458 4c87190fe64214b6eca4f63df1208c9f
    http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_m68k.deb
      Size/MD5 checksum:    62918 e3e180c6c5523703a7341c84a4e4a4df
    http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_m68k.deb
      Size/MD5 checksum:    65542 872bcdbb8cd038b3a2dea62ac7c8fdea
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_m68k.deb
      Size/MD5 checksum:    54666 4802604aedd74065e8b81d97232408c2
    http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_m68k.deb
      Size/MD5 checksum:   187356 6c5df5e058da4ce992485410dcc98ee5
    http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_m68k.deb
      Size/MD5 checksum:   425506 8d4aa93a570fba15a5d8c1f62d52753d
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_m68k.deb
      Size/MD5 checksum:  1583486 8d85e63deff4118572d47fd141a41658
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_m68k.deb
      Size/MD5 checksum:   269824 b4937a9489ab9ca86e726565e5eae8a6
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_m68k.deb
      Size/MD5 checksum:   325176 bac75344e24a7cc3c0c30a95219f4b06
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_m68k.deb
      Size/MD5 checksum:   490120 b0a8a763a09eda8dde0a2528d221f8c0
    http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_m68k.deb
      Size/MD5 checksum:    62196 66789981299a9c320dddd23e7c2f5296

  Big endian MIPS architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_mips.deb
      Size/MD5 checksum:    30888 70edc0691cf5dab348d9a9d5fbe58c25
    http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_mips.deb
      Size/MD5 checksum:    58868 406585bd9bccba087091fb0f489a451e
    http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_mips.deb
      Size/MD5 checksum:    65164 e85c2a7ea19da9e81b563e84fcd4991d
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_mips.deb
      Size/MD5 checksum:    59014 98949c4dcbe48f2b4379e17396ec0dbf
    http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_mips.deb
      Size/MD5 checksum:   237226 a425457a2b67d54db1b18058d1620624
    http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_mips.deb
      Size/MD5 checksum:   425344 f8de7160a3fb3e3a64a930a926b1501c
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_mips.deb
      Size/MD5 checksum:  1750394 5020905f56d2b79f2e8a8b29db7d5d5f
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_mips.deb
      Size/MD5 checksum:   294034 b49aeb2c271e87c1c1fb43a8baebd52f
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_mips.deb
      Size/MD5 checksum:   343772 444b95b152cb16986f91b9ee267573f6
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_mips.deb
      Size/MD5 checksum:   515344 d4997f765da28eb100b6775ff44dde58
    http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_mips.deb
      Size/MD5 checksum:    61464 9ca6745e34c308a949d1b050dee63460

  Little endian MIPS architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_mipsel.deb
      Size/MD5 checksum:    30904 ac6deff300cafef3677be545dbe5f868
    http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_mipsel.deb
      Size/MD5 checksum:    58618 23625974da0c6d77a3ad226e6612fed4
    http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_mipsel.deb
      Size/MD5 checksum:    64780 6abb60f5d14aa3c6cb2156b2ba228a41
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_mipsel.deb
      Size/MD5 checksum:    58960 6eaa6c44da9854668dd26b34445cf473
    http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_mipsel.deb
      Size/MD5 checksum:   237626 601f40058f48df8fc1b47848a05f0066
    http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_mipsel.deb
      Size/MD5 checksum:   425258 46c1756515d33fbb642c5811253bc4f1
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_mipsel.deb
      Size/MD5 checksum:  1662146 42fca9d6328e270de858ba50c3573135
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_mipsel.deb
      Size/MD5 checksum:   294360 fe6b26a455c1e10d9c814c96aba11b8c
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_mipsel.deb
      Size/MD5 checksum:   343500 ba406f263f193c0c3e06f47c3abf1720
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_mipsel.deb
      Size/MD5 checksum:   512550 f11ed9576a234a6b0c788ad77fce2df1
    http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_mipsel.deb
      Size/MD5 checksum:    61398 efbe9f8a543dd128eaee98118778ca39

  PowerPC architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_powerpc.deb
      Size/MD5 checksum:    32274 08de8250ce2a0e0d5d1d23f9c82b85d5
    http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_powerpc.deb
      Size/MD5 checksum:    69388 23cfb177aed49a059ae6ecffbd4d1f74
    http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_powerpc.deb
      Size/MD5 checksum:    67374 908acd16e7217631274d84f256f7a7bb
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_powerpc.deb
      Size/MD5 checksum:    56900 3d84f7a922aac59d342014f53477de80
    http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_powerpc.deb
      Size/MD5 checksum:   242788 92ca7303133568a9ba2ed1f6a4c019a6
    http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_powerpc.deb
      Size/MD5 checksum:   425140 18662fd754ca22a6eb2efa772a2b1144
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_powerpc.deb
      Size/MD5 checksum:  1700888 e7993b8590e7cfabe57cb1a4b61bacdd
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_powerpc.deb
      Size/MD5 checksum:   288370 654d862c906a8dba26f5c10ec148978b
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_powerpc.deb
      Size/MD5 checksum:   341792 d0375e9bc0820f5c4db08ff5d155c945
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_powerpc.deb
      Size/MD5 checksum:   510976 7baedd28debaef3b7c00174ccb4fc95c
    http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_powerpc.deb
      Size/MD5 checksum:    62286 d195a64399213a1367459e86c46842e4

  IBM S/390 architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_s390.deb
      Size/MD5 checksum:    31192 33002b92e636b429167dc34fc4c02d88
    http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_s390.deb
      Size/MD5 checksum:    63742 e70b1b4ba63e17f1c7ac97ff03a8cf93
    http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_s390.deb
      Size/MD5 checksum:    67994 26c00bff9ce74804c27bdbe82c373c37
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_s390.deb
      Size/MD5 checksum:    56166 9a2c574927dcab9bf595b1c6c9046815
    http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_s390.deb
      Size/MD5 checksum:   214800 72ded6c6d53e7bca232aa5d9cfe1051f
    http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_s390.deb
      Size/MD5 checksum:   425134 6cc5eec474fd0006bd8c9c8ffc17fea5
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_s390.deb
      Size/MD5 checksum:  1668896 eb7462ad0b00eee73f86fc09cfe89785
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_s390.deb
      Size/MD5 checksum:   284132 91df1835c62a187ec12658af9f466e5e
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_s390.deb
      Size/MD5 checksum:   346814 65566d0ae8278f0c62887d6737301d6e
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_s390.deb
      Size/MD5 checksum:   501990 d651c368529ce3656fe6941b1c768eda
    http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_s390.deb
      Size/MD5 checksum:    62788 6f292522e3d3a92b89065cfb6ae42eb5

  Sun Sparc architecture:

    http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_sparc.deb
      Size/MD5 checksum:    30874 0c289545a3bd7bfafbbb8ca613fd8cb0
    http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_sparc.deb
      Size/MD5 checksum:    64580 7570fd4ec3291dfa2bdb50c03dfe3a7e
    http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_sparc.deb
      Size/MD5 checksum:    68126 53d0d4ea0caebf21aad29339c70d11aa
    http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_sparc.deb
      Size/MD5 checksum:    54996 528c131b09831e87120e0aa34c202236
    http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_sparc.deb
      Size/MD5 checksum:   232532 180d711333ed918fed9029afa7965105
    http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_sparc.deb
      Size/MD5 checksum:   425180 2b77ee91fdd2fec2e96e2501afd4c72b
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_sparc.deb
      Size/MD5 checksum:  1671468 a67b302bc2b47ab29185b100097c5e0a
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_sparc.deb
      Size/MD5 checksum:   288788 5e3e4ff29a41137792dc14365bdcf351
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_sparc.deb
      Size/MD5 checksum:   371136 77f82fde85862525a22c96f9b048beff
    http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_sparc.deb
      Size/MD5 checksum:   502088 7ed74a18e25e38b66b486245aa244764
    http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_sparc.deb
      Size/MD5 checksum:    62348 0a1af2e1f5a8d46dffe6409418a84958


  These files will probably be moved into the stable distribution on
  its next update.

- - ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iD8DBQFBghlxW5ql+IAeqTIRArFsAJ4prBw0u1NCjJQ02dGfkdf8LPasxACgiCg+
hQ7CcIUkGA+Suk28miVBFrs=
=/YNJ
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

If you believe that your computer system has been compromised or attacked in 
any way, we encourage you to let us know by completing the secure National IT 
Incident Reporting Form at:

        http://www.auscert.org.au/render.html?it=3192

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================

-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQCVAwUBQYWFhCh9+71yA2DNAQLLzAQAilZO1bR81T/cGyow+KTAXrIiyNS9ZPCi
+tcaKj4a5Uw3ycP6Aa+P8m0UeQAxWD2XUlf/QTQCGTgpu7aapGyv91dJgoVhAGCL
wyqgJF1mY2PjYJmISmlwHhmwyy+wD6Tg7eQ8T5I5PtLe5NpvzUEbaGWuLoGx/oMx
mUYBQhHTc3A=
=+4OK
-----END PGP SIGNATURE-----