Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian DSA-3935-1: Critical PostgreSQL Authentication Flaws And Updates

debian
Calendar Grey August 10, 2017
Debian Logo
Important PostgreSQL patch released targeting various security flaws to improve database protection.
Several vulnerabilities have been found in the PostgreSQL database system: CVE-2017-7546

Summary

Several vulnerabilities have been found in the PostgreSQL database
system:

CVE-2017-7546

In some authentication methods empty passwords were accepted.

CVE-2017-7547

User mappings could leak data to unprivileged users.

CVE-2017-7548

The lo_put() function ignored ACLs.

For more in-depth descriptions of the security vulnerabilities,
please see https://https://www.postgresql.org/about/news/postgresql-anonymizer-06-pseudonymization-and-improved-anonymous-exports-2017/

For the oldstable distribution (jessie), these problems have been fixed
in version 9.4.13-0+deb8u1.

We recommend that you upgrade your postgresql-9.4 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: postgresql-9.4
CVE ID: CVE-2017-7546 CVE-2017-7547 CVE-2017-7548

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here