Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 510
Alerts This Week
Warning Icon 1 510

Ubuntu 12.10: 1789-1 Critical: PostgreSQL Remote Threat Fixes

ubuntu
Calendar Grey April 4, 2013
Scroller Ubuntu
A set of PostgreSQL security updates has been issued for Ubuntu versions 12.04, 11.10, and 10.04 to alleviate possible remote vulnerabilities.
Several security issues were fixed in PostgreSQL.

Summary

Several security issues were fixed in PostgreSQL.

Software Description:

- postgresql-9.1: Object-relational SQL database

- postgresql-8.4: Object-relational SQL database

- postgresql-8.3: Object-relational SQL database

Details:

Mitsumasa Kondo and Kyotaro Horiguchi discovered that PostgreSQL

incorrectly handled certain connection requests containing database names

starting with a dash. A remote attacker could use this flaw to damage or

destroy files within a server's data directory. This issue only applied to

Ubuntu 11.10, Ubuntu 12.04 LTS, and Ubuntu 12.10. (CVE-2013-1899)

Marko Kreen discovered that PostgreSQL incorrectly generated random

numbers. An authenticated attacker could use this flaw to possibly guess

another database user's random numbers. (CVE-2013-1900)

Noah Misch discovered that PostgreSQL incorrectly handled certain privilege

checks. An unprivileged attacker could use this flaw to possibly interfere

with in-progress backups. This issue onl...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  postgresql-9.1                  9.1.9-0ubuntu12.10

Ubuntu 12.04 LTS:
  postgresql-9.1                  9.1.9-0ubuntu12.04

Ubuntu 11.10:
  postgresql-9.1                  9.1.9-0ubuntu11.10

Ubuntu 10.04 LTS:
  postgresql-8.4                  8.4.17-0ubuntu10.04

Ubuntu 8.04 LTS:
  postgresql-8.3                  8.3.23-0ubuntu8.04.1

This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.

References

https://ubuntu.com/security/notices/USN-1789-1

CVE-2013-1899, CVE-2013-1900, CVE-2013-1901

Severity
critical
Lowest
Low
Medium
High
Critical

April 04, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.