Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Debian 8.4 DSA-2340-1 Moderate: PostgreSQL Weak Password Hashing

debian
Calendar Grey November 7, 2011
Scroller Debian
Debian Security Notice DSA-2340-1 highlights a security flaw in PostgreSQL's blowfish encryption, including guidance for updating.
magnum discovered that the blowfish password hashing used amongst others in PostgreSQL contained a weakness that would give passwords with 8 bit characters the same hash as weaker ...

Summary

For the oldstable distribution (lenny), this problem has been fixed in
postgresql-8.3 version 8.3.16-0lenny1.

For the stable distribution (squeeze), this problem has been fixed in
postgresql-8.4 version 8.4.9-0squeeze1.

For the testing distribution (wheezy) and unstable distribution (sid),
this problem has been fixed in postgresql-8.4 version 8.4.9-1,
postgresql-9.0 9.0.5-1 and postgresql-9.1 9.1~rc1-1.

The updates also include reliability improvements, originally scheduled
for inclusion into the next point release; for details see the respective
changelogs.

We recommend that you upgrade your postgresql packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Package: postgresql-8.3, postgresql-8.4, postgresql-9.0
CVE ID: CVE-2011-2483

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.