Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Fedora 27: FEDORA-2018-e2f4dca22e Notice: MySQL Security Flaw Risk

fedora
Calendar Grey August 16, 2018
Dist Fedora Esm H88
Perform an upgrade of PostgreSQL on Fedora 27 urgently to address severe security vulnerabilities and potential memory leak problems. Take prompt action!
update to 9.6.10, CVE-2018-10915 CVE-2018-10925

Summary

PostgreSQL is an advanced Object-Relational database management system (DBMS).

The base postgresql package contains the client programs that you'll need to

access a PostgreSQL DBMS server, as well as HTML documentation for the whole

system. These client programs can be located on the same machine as the

PostgreSQL server, or on a remote machine that accesses a PostgreSQL server

over a network connection. The PostgreSQL server can be found in the

postgresql-server sub-package.

update to 9.6.10, CVE-2018-10915 CVE-2018-10925

* Wed Aug 8 2018 Pavel Raiskup - 9.6.10-1

- update to 9.6.10 per release notes:

https://www.postgresql.org/docs/9.6/release-9-6-10.html

* Thu May 10 2018 Pavel Raiskup - 9.6.9-1

- update to 9.6.9 per release notes:

https://www.postgresql.org/docs/9.6/release-9-6-9.html

* Thu Mar 1 2018 Pavel Raiskup - 9.6.8-1

- update to 9.6.8 per release notes:

https://www.postgresql.org/docs/9.6/release-9-6-8.html

* Thu Feb 8 2018 Petr Kubat - 9.6.7-1

- update to 9.6.7 per release notes:

https://www.postgresql.org/docs/9.6/release-9-6-7.html

* Wed Nov 8 2017 Pavel Raiskup - 9.6.6-1

- update to 9.6.6 per release notes:

https://www.postgresql.org/docs/9.6/release-9-6-6.html

* Wed Nov 8 2017 Pavel Raiskup - 9.6.5-2

- rebase to new postgresql-setup 6.0 version, to fix CVE-2017-15097

[ 1 ] Bug #1614404 - CVE-2018-10915 postgresql: Certain host connection parameters defeat client-side security defenses [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1614404

[ 2 ] Bug #1614402 - CVE-2018-10925 postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1614402

su -c 'dnf upgrade --advisory FEDORA-2018-d8f5aea89d' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5O3TG4AQRQP7AH3KLCI73OTJC76DNUM6/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 27
Version: 9.6.10
Release: 1.fc27
Summary: PostgreSQL client programs

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here