Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Fedora 28: 2018-08550a9006 Critical: PostgreSQL Access Control Issues

fedora
Calendar Grey May 12, 2018
Dist Fedora Esm H88
Fedora 28 brings essential PostgreSQL updates focused on enhanced functionality and security, with improved access controls and robust user rights management
update to 10.4 per release notes: https://www.postgresql.org/docs/10/release-10-4.html

Summary

PostgreSQL is an advanced Object-Relational database management system (DBMS).

The base postgresql package contains the client programs that you'll need to

access a PostgreSQL DBMS server, as well as HTML documentation for the whole

system. These client programs can be located on the same machine as the

PostgreSQL server, or on a remote machine that accesses a PostgreSQL server

over a network connection. The PostgreSQL server can be found in the

postgresql-server sub-package.

update to 10.4 per release notes:

https://www.postgresql.org/docs/10/release-10-4.html

* Wed May 9 2018 Pavel Raiskup - 10.4-1

- update to 10.4 per release notes:

https://www.postgresql.org/docs/10/release-10-4.html

* Thu Apr 26 2018 Pavel Raiskup - 10.3-5

- pltcl: drop tcl-pltcl dependency (rhbz#1571181)

* Thu Apr 19 2018 Pavel Raiskup - 10.3-4

- upgrade: package plpython*.so modules

* Mon Apr 16 2018 Pavel Raiskup - 10.3-3

- upgrade: package plperl.so and pltcl.so

- upgrade: package contrib modules

- upgrade: drop dynamic libraries

* Fri Apr 13 2018 Pavel Raiskup - 10.3-2

- define %precise_version helper macro

- drop explicit libpq.so provide from *-libs

- update postgresql-setup tarball

- add postgresql-test-rpm-macros package

[ 1 ] Bug #1576773 - CVE-2018-1115 postgresql: Too-permissive access control list on function pg_logfile_rotate() [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1576773

su -c 'dnf upgrade --advisory FEDORA-2018-08550a9006' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 28
Version: 10.4
Release: 1.fc28
Summary: PostgreSQL client programs

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here