Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 11 advisory: Ocaml-Postgresql 1.12.3 Critical Escape Issue

fedora
Calendar Grey November 10, 2009
Dist Fedora Esm H88
Notification of updates for Fedora 11: a crucial security patch has been applied to ocaml-postgresql, addressing vulnerabilities in the escape function.
- New upstream version 1.12.3

Summary

This OCaml-library provides an interface to PostgreSQL, an efficient

and reliable, open source, relational database. Almost all

functionality available through the C-API (libpq) is replicated in a

type-safe way. This library uses objects for representing database

connections and results of queries.

Update Information:

- New upstream version 1.12.3. - This contains a SECURITY fix for: https://bugzilla.redhat.com/show_bug.cgi?id=529325 CVE-2009-2943 ocaml- postgresql: Missing escape function (DSA-1909-1) HOWEVER you are not protected until you change your code to use the new connection#escape_string method.

Change Log

* Fri Oct 16 2009 Richard W.M. Jones - 1.12.3-1.fc11.2 - Fix build process for new upstream tarball layout. * Fri Oct 16 2009 Richard W.M. Jones - 1.12.3-1 - New upstream version 1.12.3. - This contains a SECURITY fix for: https://bugzilla.redhat.com/show_bug.cgi?id=529325 CVE-2009-2943 ocaml-postgresql: Missing escape function (DSA-1909-1) HOWEVER you are not protected until you change your code to use the new connection#escape_string method.

References


[ 1 ] Bug #529325 - CVE-2009-2943 ocaml-postgresql: Missing escape function (DSA-1909-1) https://bugzilla.redhat.com/show_bug.cgi?id=529325

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update ocaml-postgresql' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: ocaml-postgresql
Product: Fedora 11
Version: 1.12.3
Release: 1.fc11.2
URL: Summary : OCaml library for accessing PostgreSQL databases

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here