Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian 9.6 DSA-3936-1 Moderate: PostgreSQL Security Issues

debian
Calendar Grey August 10, 2017
Debian Logo
Multiple security flaws within PostgreSQL have been discovered and need urgent remediation and patches on Debian platforms.
Several vulnerabilities have been found in the PostgreSQL database system: CVE-2017-7546

Summary

Several vulnerabilities have been found in the PostgreSQL database
system:

CVE-2017-7546

In some authentication methods empty passwords were accepted.

CVE-2017-7547

User mappings could leak data to unprivileged users.

CVE-2017-7548

The lo_put() function ignored ACLs.

For more in-depth descriptions of the security vulnerabilities,
please see https://www.postgresql.org/about/news/2017-08-10-security-update-release-1772/

For the stable distribution (stretch), these problems have been fixed in
version 9.6.4-0+deb9u1.

We recommend that you upgrade your postgresql-9.6 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Package: postgresql-9.6
CVE ID: CVE-2017-7546 CVE-2017-7547 CVE-2017-7548

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here