Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2017.1988 postgresql-9.4 security update 11 August 2017 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: postgresql-9.4 postgresql-9.6 Publisher: Debian Operating System: Debian GNU/Linux 8 Debian GNU/Linux 9 UNIX variants (UNIX, Linux, OSX) Impact/Access: Denial of Service -- Existing Account Unauthorised Access -- Remote/Unauthenticated Access Confidential Data -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2017-7548 CVE-2017-7547 CVE-2017-7546 Original Bulletin: http://www.debian.org/security/2017/dsa-3935 http://www.debian.org/security/2017/dsa-3936 Comment: This bulletin contains two (2) Debian security advisories. This advisory references vulnerabilities in products which run on platforms other than Debian. It is recommended that administrators running postgresql-9.4 or postgresql-9.6 check for an updated version of the software for their operating system. - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - - ------------------------------------------------------------------------- Debian Security Advisory DSA-3935-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 10, 2017 https://www.debian.org/security/faq - - ------------------------------------------------------------------------- Package : postgresql-9.4 CVE ID : CVE-2017-7546 CVE-2017-7547 CVE-2017-7548 Several vulnerabilities have been found in the PostgreSQL database system: CVE-2017-7546 In some authentication methods empty passwords were accepted. CVE-2017-7547 User mappings could leak data to unprivileged users. CVE-2017-7548 The lo_put() function ignored ACLs. For more in-depth descriptions of the security vulnerabilities, please see https://www.postgresql.org/about/news/1772/ For the oldstable distribution (jessie), these problems have been fixed in version 9.4.13-0+deb8u1. We recommend that you upgrade your postgresql-9.4 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org - -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlmMyugACgkQEMKTtsN8 Tjbhrw/+OA9HQ3H9S96IkZ3q4qV9EtZofNE2Dc7KMqfZcTb7pDtHs5NJNvjjQbB2 C7qd6FHCZkcm/07Z2eQwS8b6hlMylAAOFlGuy+7J+1wfiIQOJ+B5DgUnwVngvsjC Sl1Oi8f3qfaZitcT1HVus3cVrIzGcZwiZpOeyGtpX83pI5ydFA6kiKYgRh0+pwRe Z6RcRWEOS80VUbpJuJcE6szWqv5TDq9jmuadEYFgY4kypefewnGE7lUZPkrcwsm4 QUz/nxswPthWUTEmpg55pWQDl2BEp/GuaHEetYEAKy/tgBAypWs5rhEYV0F007DS L3u5Cs5yzmSJeUCEHFJ+ovox1DOdRpInn9+B9NXJAUz1cDdPFG7JJbMC4nshigrT rOm0BxR7cQNnUTYl76W1cLRsdsHCyh12sbLJdevEZ48QPX/pQu9vuC0+yqxdbFVe ogUBcWizJ/kJQMBDgBv2AU59H8S/J1jFdKzQ3JMQ81dv/NDDGe7qVaWufQ32RUVS Dx1ft/HAbltqcyPtbNUGCtmb3d5hyLPY69/+jHtWKAGW+/0HFIpCS/CTyYZEikLB hkNj2WpxZdzWnpBS3UeYsvFyxJLWqxDUY6X8QpGZYrb1Y9Vq42BkcQSTbkT3vp4J DxPWZfw/ak/IiAQ6mJkn5CHMZHwXm0hWzmo1BL698cHInh1vaLo= =qCEo - -----END PGP SIGNATURE----- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - - ------------------------------------------------------------------------- Debian Security Advisory DSA-3936-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 10, 2017 https://www.debian.org/security/faq - - ------------------------------------------------------------------------- Package : postgresql-9.6 CVE ID : CVE-2017-7546 CVE-2017-7547 CVE-2017-7548 Several vulnerabilities have been found in the PostgreSQL database system: CVE-2017-7546 In some authentication methods empty passwords were accepted. CVE-2017-7547 User mappings could leak data to unprivileged users. CVE-2017-7548 The lo_put() function ignored ACLs. For more in-depth descriptions of the security vulnerabilities, please see https://www.postgresql.org/about/news/1772/ For the stable distribution (stretch), these problems have been fixed in version 9.6.4-0+deb9u1. We recommend that you upgrade your postgresql-9.6 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org - -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlmMyu8ACgkQEMKTtsN8 TjY4TA//ZeCZDdLmLZE09WcDTwpsvcb6ZEdEj3jekMswPP6WHkZlnpVSX711Cyv0 veck/xojcIdGl6oki2/OM7ErJ3L7eteGLqswzWmsOk7lWSya5/EJCIV+DXGOhqnI ESSADLI+hLwoFqxGjYwbLfpyo7Mxpwfw42fRVVC++T2+7cG4BBsLJh++sOL/tIiD OEhVgK5NK+4r7E8ZpCcLW4BZBMPt6V31Pr0sXSa8gQ7D7LbNvI+v/L5cgZTL8Ewf WWf9NyWDgY06s+BvNxtNXwoeT9WTwigV3IFuwe5pmoRlwNdqGxIZBdUBd9tXDY1Y T6BrpHa0dyZVhNFL8TM8o8kOzZjpg5hiDzXDfeyGpOqEy6psdNll4kO66/XN0yoF LpQ60uMlmNso99vAuyY9S6/DoMRKVQifJT7epA8y0lF4T/YG0YN6nCeYwSsFQGOU gAhTgQIxxYnmu9pBDS7eFVijxBs7GfakGMF/VZ4VQ+1R3DGFncbyCVdJqiVUw9Db t7vym8cfUjaox9LuedGhXBdBxoy2cBdwvJ8BlAbHhmQ7O+mVrDbp1nqBN1bQaZo8 mWdaLdNM2PxVW5RGGYjSLdE7VgtCDEacTxiea1S4Q/ZvnoPV7qwvwo9a5RoaB+v3 5hd9SDcBvhrTNHDr8tRhr+yHMVjQZ8tvfMlR8WmLK7xM2Pnsdpo= =mzAD - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: http://www.auscert.org.au/render.html?cid=1980 =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBWY0BpYx+lLeg9Ub1AQhetA//dZZAwdiJEjkf9o4dWQDnaKI4927t/xuB Bf6Mh05oEpjgyhd1S/aD8E6QoZQqKFWI3ZjEYB/dqzO36zrUKdiSg47eiVizt+Wd cUiGvqSSk6cAcRKwpiEC4m+HDOeQNUMTEnZ08fkLC4qHKoZ+iif2e/Ub64ZBJN+u NpoAkB2pEY2Jlw2m++CZMcsBw/6/5SQnffIcDjH3DFanvKhdesq0wHq+q+wO9sOB 0EaBPGXn9AOtC1uR/TX9NxCreO7xAwG1TaARfCwFpiJcFNtV25yiDv3l0p73Jn1z cTVl5ckPX+lH/pesm6QdkobLBpVH+YRYOMt1y0UkU38R0JXr7M+1URamZYUGYVA9 /PyVjB7SFeZTDfU7dG0RGZqWDSUe4hyI1h/Epamq7pPxT0h5MePj3RsdSWPcPQnW PC97Dy6sk0UKBM/AFIqwlH+U+gxBpjXVbetiFOhyDqkmLjNNP6ucbfKfcjr3VAul LJ7iM2YnkWyTt2V3kUNnnc6YrC5JhB/+l60mWzhzPj8yvHVqLoFBe3hr5l/q2WMS jYhqGgYLFfK9oczo1tDFMLG17+B8daWZQ7So1nQ6ph8ACwRUoYo0vC1xwNOKfdfP RxheVVK3P4PKXgEOSRmzCFLLp7lW7Tie+s0BbO9HQUZgHWtluuqOgMmAX52EaGjh rBTKSvhm+9o= =9M0E -----END PGP SIGNATURE-----