Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian Jessie: DSA-3851-1 Critical: PostgreSQL Data Leak Issues

debian
Calendar Grey May 12, 2017
Debian Logo
Debian releases new PostgreSQL 9.4 patch to fix critical security flaws, notably those related to data leakage and TLS compliance problems.
Several vulnerabilities have been found in the PostgreSQL database system: CVE-2017-7484

Summary

Several vulnerabilities have been found in the PostgreSQL database
system:

CVE-2017-7484

Robert Haas discovered that some selectivity estimators did not
validate user privileges which could result in information
disclosure.

CVE-2017-7485

Daniel Gustafsson discovered that the PGREQUIRESSL environment
variable did no longer enforce a TLS connection.

CVE-2017-7486

Andrew Wheelwright discovered that user mappings were insufficiently
restricted.

For the stable distribution (jessie), these problems have been fixed in
version 9.4.12-0+deb8u1.

We recommend that you upgrade your postgresql-9.4 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: postgresql-9.4
CVE ID: CVE-2017-7484 CVE-2017-7485 CVE-2017-7486

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here