Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
202

openSUSE: 2020:1868-1 Critical: Salt Security Update with Credential Fixes

An update that solves three vulnerabilities and has 7 fixes is now available.. openSUSE Security Update: Security update for salt ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1868-1 Rating: critical References: #1159670 #1175987 #1176024 #1176294 #1176397 #1177867 #1178319 #1178361 #1178362 #1178485 Cross-References: CVE-2020-16846 CVE-2020-17490 CVE-2020-25592 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that solves three vulnerabilities and has 7 fixes is now available. Description: This update for salt fixes the following issues: - Avoid regression on "salt-master": set passphrase for salt-ssh keys to empty string (bsc#1178485) - Properly validate eauth credentials and tokens on SSH calls made by Salt API (bsc#1178319, bsc#1178362, bsc#1178361, CVE-2020-25592, CVE-2020-17490, CVE-2020-16846) - Fix disk.blkid to avoid unexpected keyword argument '__pub_user'. (bsc#1177867) - Ensure virt.update stop_on_reboot is updated with its default value. - Do not break package building for systemd OSes. - Drop wrong mock from chroot unit test. - Support systemd versions with dot. (bsc#1176294) - Fix for grains.test_core unit test. - Fix file/directory user and group ownership containing UTF-8 characters. (bsc#1176024) - Several changes to virtualization: * Fix virt update when cpu and memory are changed. * Memory Tuning GSoC. * Properly fix memory setting regression in virt.update. * Expose libvirt on_reboot in virt states. - Support transactional systems (MicroOS). - zypperpkg module ignores retcode 104 for search(). (bsc#1159670) - Xen disk fixes. No longer generates volumes for Xen disks, but the corresponding file or block disk. (bsc#1175987) - Invalidatefile list cache when cache file modified time is in the future. (bsc#1176397) - Prevent import errors when running test_btrfs unit tests This update was imported from the SUSE:SLE-15-SP1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-1868=1 Package List: - openSUSE Leap 15.1 (noarch): salt-bash-completion-3000-lp151.5.30.1 salt-fish-completion-3000-lp151.5.30.1 salt-zsh-completion-3000-lp151.5.30.1 - openSUSE Leap 15.1 (x86_64): python2-salt-3000-lp151.5.30.1 python3-salt-3000-lp151.5.30.1 salt-3000-lp151.5.30.1 salt-api-3000-lp151.5.30.1 salt-cloud-3000-lp151.5.30.1 salt-doc-3000-lp151.5.30.1 salt-master-3000-lp151.5.30.1 salt-minion-3000-lp151.5.30.1 salt-proxy-3000-lp151.5.30.1 salt-ssh-3000-lp151.5.30.1 salt-standalone-formulas-configuration-3000-lp151.5.30.1 salt-syndic-3000-lp151.5.30.1 References: https://www.suse.com/security/cve/CVE-2020-16846.html https://www.suse.com/security/cve/CVE-2020-17490.html https://www.suse.com/security/cve/CVE-2020-25592.html https://bugzilla.suse.com/1159670 https://bugzilla.suse.com/1175987 https://bugzilla.suse.com/1176024 https://bugzilla.suse.com/1176294 https://bugzilla.suse.com/1176397 https://bugzilla.suse.com/1177867 https://bugzilla.suse.com/1178319 https://bugzilla.suse.com/1178361 https://bugzilla.suse.com/1178362 https://bugzilla.suse.com/1178485 -- . Important openSUSE upgrade for salt addresses multiple concerns and integrates eight crucial patches for both security and performance enhancements.. openSUSE Security Update, salt software, critical fixes, patch process. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 07, 2020 Critical OpenSUSE
87

Debian: DSA-1463-1 Important Local Vulnerabilities in PostgreSQL

Several local vulnerabilities have been discovered in PostgreSQL, an object-relational SQL database. It was discovered that the DBLink module performed insufficient credential validation. This issue is also tracked as CVE-2007-6601, since the initial upstream fix was incomplete.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1463-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff January 14, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : postgresql-7.4 Vulnerability : several Problem type : local Debian-specific: no CVE Id(s) : CVE-2007-3278 CVE-2007-4769 CVE-2007-4772 CVE-2007-6067 CVE-2007-6600 CVE-2007-6601 Several local vulnerabilities have been discovered in PostgreSQL, an object-relational SQL database. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-3278 It was discovered that the DBLink module performed insufficient credential validation. This issue is also tracked as CVE-2007-6601, since the initial upstream fix was incomplete. CVE-2007-4769 Tavis Ormandy and Will Drewry discovered that a bug in the handling of back-references inside the regular expressions engine could lead to an out of bands read, resulting in a crash. This constitutes only a security problem if an application using ProgreSQL processes regular expressions from untrusted sources. CVE-2007-4772 Tavis Ormandy and Will Drewry discovered that the optimizer for regular expression could be tricked into an infinite loop, resulting in denial of service. This constitutes only a security problem if an application using ProgreSQL processes regular expressions from untrusted sources. CVE-2007-6067 Tavis Ormandy and Will Drewry discovered that the optimizer for regular expression could be tricked massive ressource consumption. This constitutes only a security problem if an application using ProgreSQL processes regular expressions from untrusted sources. CVE-2007-6600 Functions in index expressions could lead to privilege escalation. For a more in depth explanation please see the upstream announce available at . The unstable distribution (sid) no longer contains postgres-7.4 For the stable distribution (etch), these problems have been fixed in version 7.4.19-0etch1. For the old stable distribution (sarge), some of these problems have been fixed in version 7.4.7-6sarge6 of the postgresql package. Please note that the fix for CVE-2007-6600 and for the handling of regular expressions hasn't been backported due to the intrusiveness of the fix. We recommend to upgrade to the stable distribution if these vulnerabilities affect your setup. We recommend that you upgrade your postgresql-7.4 packages. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian 3.1 (oldstable) - ----------------------Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, m68k, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 9952102 d193c58aef02a745e8657c48038587ac Size/MD5 checksum: 198884 4cf8d83170ab5dcf6b0a36790ff0de9f Size/MD5 checksum: 985 5111d74c719c877925a5d85609cc3dfd Architecture independent packages: Size/MD5 checksum: 2397446 0dbaddc80dedb89399383f50b3185f90 alpha architecture (DEC Alpha) Size/MD5 checksum: 415967602d52d64badb49540044f0c043dfc222 Size/MD5 checksum: 141162 f48f62847ea6ab3d18c149292d53ad42 Size/MD5 checksum: 63744 2e685a6a05c294febf647f3a89623ca5 Size/MD5 checksum: 549576 6ffd26502a86ce35795cf2880fd94243 Size/MD5 checksum: 83518 7707b66bcf3ef2c6d12a1370653c520c Size/MD5 checksum: 106162 3a22d0b149b077f2f7423cf8cc4e39f5 Size/MD5 checksum: 609578 f9001bb5f34bd15c8049572e7e92ea77 Size/MD5 checksum: 708774 503aa5cc62a79ac423b42a1df77ca71e Size/MD5 checksum: 241042 14a65714266dfd17be562efe9decc9e7 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 3890318 ab188392e9dedbb954daceb9538ed693 Size/MD5 checksum: 521046 eb29cf25c1ce4d985b9f3d2097e9de91 Size/MD5 checksum: 80546 bd5e2c34fa3525ceb925a1a3ea976b17 Size/MD5 checksum: 97772 1a8b6015bb1b57dfc7d7f4c24e14841e Size/MD5 checksum: 560368 55a06e965a14aa05f5f8a187282763d9 Size/MD5 checksum: 132534 0d77509c54031ffc0aa2db5442b586f6 Size/MD5 checksum: 211704 a67c71dd7947c52a5b6ef87f04afe984 Size/MD5 checksum: 657242 cf41300f710b05d71a8c56c7e532756a Size/MD5 checksum: 57594 836fce144f64af229bbbed896e960bdc arm architecture (ARM) Size/MD5 checksum: 533680 c10d734fefa175d5cdac7a37c83dc1c3 Size/MD5 checksum: 123800 5e0120a6144352672a76f2b5af9cca5b Size/MD5 checksum: 3796454 98dbaecbb4d88e7714221704672bd839 Size/MD5 checksum: 94016 31c0a8d52f3f763bd202e016a1f4f426 Size/MD5 checksum: 77278 f689e24f3e726e343073a3ea3d814651 Size/MD5 checksum: 632996 9b9a76ec9c4d7be8d33451bac7f07293 Size/MD5 checksum: 57844 f57242a7ff0d30872c85ec21bed5b9ce Size/MD5 checksum: 522376 2be388acb30f4172633d07c7039d5fdb Size/MD5 checksum: 219026 74f6ac6c0c98af6db709b849227ed76c hppa architecture (HP PA RISC) Size/MD5 checksum: 136022 6f4dff891d1016bf2a886eeeda6ebb0f Size/MD5 checksum: 689710 4c2509574683d58bb0160f3624410289 Size/MD5 checksum: 218882 e4b31ea91f91389039588a6cd2e08983 Size/MD5 checksum: 85090 c463769af8623db15a9bbce167307c9c Size/MD5 checksum: 105768 943f2b199c5849f742230f4783abf3b6 Size/MD5 checksum: 525076 1f2a82d696e1a181eb9455e3180473e5 Size/MD5 checksum: 4264782 35578deafd5d1fcb585840699bcdf02e Size/MD5 checksum: 60008 0312d8b105ce211b158cdf14edb456b5 Size/MD5 checksum: 573442 7838955c1af1ad00228f36dc09c30cf2 i386 architecture (Intel ia32) Size/MD5 checksum: 541118 7fe4064b57a43221103e51f05af1b241 Size/MD5 checksum: 209068 020165bfb6274dbbd1ea9c379831de0e Size/MD5 checksum: 3801078 a61c60740a6d17ea3559ce5e7afbbdca Size/MD5 checksum: 129494 bf6b4fd7745c2baad3f2cd740905c337 Size/MD5 checksum: 79452 b85a163131bbf527aad45eafc1629196 Size/MD5 checksum: 517364 c02b7cc603534f7b0f86433c66d09918 Size/MD5 checksum: 97454 751eeba33bdd9443a2e1b78f106bb76f Size/MD5 checksum: 628026 c1b8e6c7265ad11746d802d67e312f58 Size/MD5 checksum: 57122 abd1d8cf001392e81ac908528bdd2c51 ia64 architecture (Intel ia64) Size/MD5 checksum: 61898 689af0f1bf28e6b265f4b28211217184 Size/MD5 checksum: 93130 312573c0d92d8197ca631aec0be32188 Size/MD5 checksum: 778768 02b361de31dd13f26d06dda16843ee16 Size/MD5 checksum: 118808 e2a677cef0610f09c920c457281649c6 Size/MD5 checksum: 251286 42f13551c91dbb58eca1c0f2e49cc5dd Size/MD5 checksum: 4410040 fb93d382d0deb2cda48093e15ea57a55 Size/MD5 checksum: 153890 2333d3b251dcd4d012aceb6ac5a0606a Size/MD5 checksum: 683038 e68e266df15de66a1b9a86d646aab968 Size/MD5 checksum: 544838 a581a217fc427ba2bd2094f44769c203 m68k architecture (Motorola Mc680x0) Size/MD5 checksum: 611794 531b7624c28dc2d9bb79afb0556a1c3b Size/MD5 checksum: 78252 87dee334387ba82628b1846c1a4a533c Size/MD5 checksum: 126586 88fccc95b8730baa5b2803b632b602cc Size/MD5 checksum: 91236 8cde3c525b9922067a944e4c0ea4311a Size/MD5 checksum: 195272 2fec67144b8795067e327a8b1e59ed50 Size/MD5 checksum: 3974020 47544f409bd0195732e4dc22cd566285 Size/MD5 checksum: 55226 714c91b096d1686f54c5811ba17938be Size/MD5 checksum: 511512 3743fffc63fb1b596f386af1ab72e032 Size/MD5 checksum: 508556 f780c1a8c92c27b0c79f70b21be6c26e mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 4171984 b8deac5f777223c70e6d434cf66aef17 Size/MD5 checksum: 129692 dfe185668151833d4f557472ccc66775 Size/MD5 checksum: 82070 447b2e13f541ec14d4c5af87cf79ed77 Size/MD5 checksum: 97058 18d5cf38957d4118340f4f0a73aef09d Size/MD5 checksum: 583180 858c5867bf7e47fe4e8019d45f4a943a Size/MD5 checksum: 57560 5b55c98aaa0dbb1f935d2c0202aece15 Size/MD5 checksum: 522634 be2a971d2197d0ac35c21921dbf75d8e Size/MD5 checksum: 644504 7e1f7daa70ce7b73995f72121c7e630f Size/MD5 checksum: 210998 b3a21ecb4a2902be309831f8b66c06b7 powerpc architecture (PowerPC) Size/MD5 checksum: 131102 2de58454b2272b9392fc3c0d4d6e5cf8 Size/MD5 checksum: 212452 f3483cd61d26dbf4740723311dc31832 Size/MD5 checksum: 4205092 aad575d912bcbd38581740723809f1f7 Size/MD5 checksum: 56586 05dc9cc42382ff0d2669046216983855 Size/MD5 checksum: 688664 8a8c6109e9031bdea87146fa1a877db3 Size/MD5 checksum: 85966 e687d2c83352742f451f8ed6ff093c74 Size/MD5 checksum: 517984 a266aa670fd61e40e4e211fe78255094 Size/MD5 checksum: 101766 35dc639d70bedf29e9ffa0921a1426d4 Size/MD5 checksum: 566322 b129b19900fbcda12963a79756a3da7d s390 architecture (IBM S/390) Size/MD5 checksum: 58346 d2fd52430dd8168e116b2b225309d589 Size/MD5 checksum: 4162992 a3f994afd5d36704910b2c74aa4209a8 Size/MD5 checksum: 99100 3843779ed7853e80d2e32250f0c71531 Size/MD5 checksum: 81658 f102ac494e0a726a2d131e152921b49b Size/MD5 checksum: 521830367bd789c9314c71d7d3281dfe167c40 Size/MD5 checksum: 550498 549f280c019df51e0efa028378f21e55 Size/MD5 checksum: 668000 7fde374e13919a97172ba352c0756d0b Size/MD5 checksum: 134862 8a497e76e09f69732b214c144370ecea Size/MD5 checksum: 209626 64d6ca8b28090efc8463e88291961cea sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 635624 162e1309fd6d5d7300f008a09e8f9d2a Size/MD5 checksum: 536856 73bcc6108275d509ba68e6659d531da5 Size/MD5 checksum: 515712 b760f0e0a4475bfbf3b86b7f67b036ef Size/MD5 checksum: 57448 39f97a025e02546e1abc61aa3d295432 Size/MD5 checksum: 94926 e9ed8ba7eec4b30524f0814d614d2633 Size/MD5 checksum: 128916 4f04fd4bbfb526bf039dbc905327c96f Size/MD5 checksum: 79238 9fa66c130e9c67786c863d9695349d93 Size/MD5 checksum: 4091668 82270dcb3a7d581671b3778d07da53f7 Size/MD5 checksum: 207164 17a5107abfbc940a9506c168dbc33dcd Debian 4.0 (stable) - -------------------Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 1126 7ee8eddca94332da692274ba8cfe7c32 Size/MD5 checksum: 10031202 b2b5c751263ddbe930f968f27681c862 Size/MD5 checksum: 33402 ad11d2450a6067420202adc76be2f3ca Architecture independent packages: Size/MD5 checksum: 1282356 cd876c31c255ffd93961a8b7648fd1ce Size/MD5 checksum: 525244 a2c72ce7fec9195113d71cda830583b4 alpha architecture (DEC Alpha) Size/MD5 checksum: 126270 d9f45bddaaa20c7c3c8dacdb0b126d0c Size/MD5 checksum: 123126 26eac227d035c7dd4524a9c9ea7246ef Size/MD5 checksum: 3546636 984cda2fe70da0511fa470c6e224f070 Size/MD5 checksum: 127228 ffc96d392dedf11dec1bcc2b2c93b17f Size/MD5 checksum: 1172704 4f4503c37422059e5f2833181f481244 Size/MD5 checksum: 636666 d69ae564ae5b1a2a20de968c131c9b92 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 1127736a0b428bde1bd1d130a5aa05051e5451f Size/MD5 checksum: 3445256 4984aa6a435832946830b0d7f73cf783 Size/MD5 checksum: 121880 564e768bbcd654bcc924956f9439f212 Size/MD5 checksum: 125338 441dcc412f163b19f7e816936a65da90 Size/MD5 checksum: 126472 a99b78d8a2a19c7d2245b702bf6e9c41 Size/MD5 checksum: 595342 8341694fdedbcf09c1b8e553657c149c arm architecture (ARM) Size/MD5 checksum: 1101412 90effd39f5b9c7685b076140284d8e6d Size/MD5 checksum: 120820 65acbc66eba101b81cbfbf22c2a1ecc0 Size/MD5 checksum: 126252 039af0f03d68c6b4495a03cc21b41794 Size/MD5 checksum: 3387574 1eef8106b5558734d65a1c0553014628 Size/MD5 checksum: 578256 3db09722ab75de60d3b9bbd537a4df73 Size/MD5 checksum: 124170 553b1756c43b12bab07d7e0fc150db92 hppa architecture (HP PA RISC) Size/MD5 checksum: 129136 a9e76967bd6caa10b34dcbde48f5d3fa Size/MD5 checksum: 1163576 6da46c94091fc770954ddefb200cc3d8 Size/MD5 checksum: 627366 a2055376628141b0c7bd59302fc85087 Size/MD5 checksum: 128794 97ffabd074884be929fc8c7142e66250 Size/MD5 checksum: 123884 4b996528d04dd18cc8c4b38d6d06a562 Size/MD5 checksum: 3859966 30958a149b43aa1a8dbcee57d1cfb04d i386 architecture (Intel ia32) Size/MD5 checksum: 3382724 5cac69d1baa16515d9bc144400683643 Size/MD5 checksum: 571698 d0f1dcad3e13a6130cb467116a40ee1b Size/MD5 checksum: 125898 92dd9cd7a1fbbb8656d700723689775d Size/MD5 checksum: 121542 812343b3e8d4ffb11584ff8f671d568d Size/MD5 checksum: 1110108 c5223d3a56a48fb86728a5f0e034e6e4 Size/MD5 checksum: 123904 ed3cc8ed8a76701355a7264dad818f01 ia64 architecture (Intel ia64) Size/MD5 checksum: 134522 3d0c2a7c9fac7a3189db054986b3b3f3 Size/MD5 checksum: 1252500 d63403fe9355d9fc6d0d29e27f2fe67c Size/MD5 checksum: 126698 9d53bea890db3119f05bb2cebc68ce18 Size/MD5 checksum: 713478 39bf3a3712a2a5a3ea882afb5b67b5b5 Size/MD5 checksum: 1349167e32f5c3d1fa8681654bb9620c0c181e Size/MD5 checksum: 3908578 7e88c1e836abd8896ad3e5f88238e539 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 1118560 cd2d61630829a2c813545b1507bbfe80 Size/MD5 checksum: 120068 579944a08e61f7c96e63da4fcf7844b2 Size/MD5 checksum: 3685454 4167f3244a8898b4d3201af3275ef33b Size/MD5 checksum: 127038 af6080bbdeac31c7a7598dee1bddafce Size/MD5 checksum: 125852 29991ab776d12076a5eddb594803524b Size/MD5 checksum: 574252 bc13471f8459c86073d74c34e8a7cfd9 powerpc architecture (PowerPC) Size/MD5 checksum: 3753004 1c8f61cc127b57b36f5a6432907bbc17 Size/MD5 checksum: 625766 eeca1931b318cf9d6fc0d8c2ccda18f2 Size/MD5 checksum: 126672 4d2f44918d6137fbfcbaa29708ef0881 Size/MD5 checksum: 1130460 f2e2e11ed15daf5567f82b6cc726cf1e Size/MD5 checksum: 128438 bc035033cc62e410e15387cdc8bedb83 Size/MD5 checksum: 123208 145509fdae51ac4ae0dfe252e725c3ad s390 architecture (IBM S/390) Size/MD5 checksum: 126332 1b3803ef37e9793fea44b35a0f89bbb3 Size/MD5 checksum: 126914 e639a9a7b3ccb9dec165e769b4474291 Size/MD5 checksum: 3797432 c0230064ae5d8d17facf949627993011 Size/MD5 checksum: 121660 3463563991970d8a0954bd3c7439fdde Size/MD5 checksum: 1134292 58a4d72e7557b1d80c4a223f02ff1dcc Size/MD5 checksum: 608494 bfabdaa1575143549326eed40f6d9662 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 121556 f132d46f9015bc9ba40c99a08b20878c Size/MD5 checksum: 574956 bdc86c5cae2f38a2039007c20956d6c0 Size/MD5 checksum: 1103026 0b69fd93c608056fc55f42793425aaa6 Size/MD5 checksum: 126768 bcb02babdd396a2856bb964e330457cf Size/MD5 checksum: 3674260 5595b5c9242b3a4f068a5ba11f103c2e Size/MD5 checksum: 125054 0d7a789fb3d1b7bf9287767f5f6230e4 These files will probably be moved into the stable distribution on its next update. ----------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance postgresql-7.4 components to address various local security flaws in Debian. Important security notice enclosed.. PostgreSQL Vulnerabilities, Debian Advisory, Local Issues. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 14, 2008 Important Debian
87

Debian DSA-1460-1 Critical: PostgreSQL Local Issues and DoS Risks

It was discovered that the DBLink module performed insufficient credential validation. This issue is also tracked as CVE-2007-6601, since the initial upstream fix was incomplete.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1460-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff January 13, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : postgresql-8.1 Vulnerability : several Problem type : local Debian-specific: no CVE Id(s) : CVE-2007-3278 CVE-2007-4769 CVE-2007-4772 CVE-2007-6067 CVE-2007-6600 CVE-2007-6601 Several local vulnerabilities have been discovered in PostgreSQL, an object-relational SQL database. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-3278 It was discovered that the DBLink module performed insufficient credential validation. This issue is also tracked as CVE-2007-6601, since the initial upstream fix was incomplete. CVE-2007-4769 Tavis Ormandy and Will Drewry discovered that a bug in the handling of back-references inside the regular expressions engine could lead to an out of bands read, resulting in a crash. This constitutes only a security problem if an application using ProgreSQL processes regular expressions from untrusted sources. CVE-2007-4772 Tavis Ormandy and Will Drewry discovered that the optimizer for regular expression could be tricked into an infinite loop, resulting in denial of service. This constitutes only a security problem if an application using ProgreSQL processes regular expressions from untrusted sources. CVE-2007-6067 Tavis Ormandy and Will Drewry discovered that the optimizer for regular expression could be tricked massive ressource consumption. This constitutes only asecurity problem if an application using ProgreSQL processes regular expressions from untrusted sources. CVE-2007-6600 Functions in index expressions could lead to privilege escalation. For a more in depth explanation please see the upstream announce available at . For the unstable distribution (sid), these problems have been fixed in version 8.2.6-1 of postgresql-8.2. For the stable distribution (etch), these problems have been fixed in version postgresql-8.1 8.1.11-0etch1. The old stable distribution (sarge), doesn't contain postgresql-8.1. We recommend that you upgrade your postgresql-8.1 (8.1.11-0etch1) package. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian 4.0 (stable) - -------------------Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 35762 c4858189bfd1ef7b426d7ad337293a00 Size/MD5 checksum: 11444400 9eadd7e16f547a8ce1e0eec5de96632e Size/MD5 checksum: 1171 118e1cfc403a8299dfa76fc1e267342e Architecture independent packages: Size/MD5 checksum: 1597344 fc757ca9e80c49309458624a4d6fd3ab alpha architecture (DEC Alpha) Size/MD5 checksum: 671056 d60a96a721b26b2b5bd1c5ee7ef10de0 Size/MD5 checksum: 4485032 288e073ec4ba0291155d26e8bda27d89 Size/MD5 checksum: 615002 9f7b83a128b100c1848f791aa3fd4bc5 Size/MD5 checksum: 179300 bf2196f4fe7fa598045630d8cf6182bd Size/MD5 checksum: 288728 451ad14dc38e9dd85854b0bce01f9074 Size/MD5 checksum: 1943443e900434f89cbcaf48ebac01df90acfd Size/MD5 checksum: 385616 5930618352cb115115b3628f39ab65a1 Size/MD5 checksum: 192240 88a3512b394d91c305cd3965e4a5037e Size/MD5 checksum: 372570 e5ff8fb09312ffbcfe8f1850c4a94f5b Size/MD5 checksum: 179692 ac196e73f2b58d35dbf144a97ad0c51a Size/MD5 checksum: 169342 8443f4b7fbc010308c8942616dd6571b Size/MD5 checksum: 1506432 d404f1b70312c03ebcfcb803361cc969 Size/MD5 checksum: 185872 63456965d24105c5bb844e380d3fd72e amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 167984 dff8b8ccb1d9441bcd8a7babcd5e054c Size/MD5 checksum: 358830 de2a6906b2f7be6650482c869b67f1bf Size/MD5 checksum: 4359520 d2c7cfcd6b225fdc5e3620bc6f914e70 Size/MD5 checksum: 188626 4e0aeb2c9d1709a5721d5dea2f37ca28 Size/MD5 checksum: 341616 8f86216c386e542945931fea3f486318 Size/MD5 checksum: 184302 e1f38d75fe5f28fe76148c398f82d309 Size/MD5 checksum: 178564 16268efa8e610c989f23958780956c5f Size/MD5 checksum: 613692 0293b6deea8ab2228c03f35c4c7a2cba Size/MD5 checksum: 177974 ce66da98adc202d33eba56c4a9411401 Size/MD5 checksum: 281150 1ecebfe7616c4094cb21f7b68bc2a6d5 Size/MD5 checksum: 189772 7fa219d74a3999dc61ce723bd120887c Size/MD5 checksum: 634182 11a0c0d0b6fff605416814f9d0df5d42 Size/MD5 checksum: 1457502 cb240c04cf79d35d32323c6913f66b23 arm architecture (ARM) Size/MD5 checksum: 4285426 2a56c74bfda490554cc60451de919f6b Size/MD5 checksum: 181696 70fc8536616b8cf2fdc8072133b8431f Size/MD5 checksum: 346224 eddc2770bd67c88f4e967eea57cdef18 Size/MD5 checksum: 614330 89374bf3135141b1ef04d1c49972eb21 Size/MD5 checksum: 189254 dbff7d9333154fa84bd75bfdbab546f8 Size/MD5 checksum: 325418 a987851b027f00c18f98fb89b70e9600 Size/MD5 checksum: 178052 d029ce834b5101213e439832ee090d65 Size/MD5 checksum: 270090 9989a567df8f83f7fe7f571b05409e4f Size/MD5 checksum: 1424902edd28eebef6e21ad8b1cea77d7e5dd47 Size/MD5 checksum: 167560 754baff8e971dacc7b9cf139c2fe7ce8 Size/MD5 checksum: 185666 6f891583878dedde5784e57f946f8b18 Size/MD5 checksum: 602668 4ea6bd89094088ab7bf1bcbc212d20d1 Size/MD5 checksum: 176828 0d5952a2df2f37a02e713410e4ad5307 hppa architecture (HP PA RISC) Size/MD5 checksum: 195148 0468f2250bd62ab711ce551f43a7c0ab Size/MD5 checksum: 180664 91671b1cdbf9902fc1b0feeedaf9c13a Size/MD5 checksum: 1506136 f10ec552370d4ee866d5033566e455c8 Size/MD5 checksum: 286222 e331ce08e73a60ad7ae335bd3d07cb56 Size/MD5 checksum: 661174 a05f0976f97eaeb3ac1fda9d4456a408 Size/MD5 checksum: 191426 5fcb2e9052080f2c309d1d1270b4d7c1 Size/MD5 checksum: 169556 596adfb8a5e43e3c913a83a0c1ea83f7 Size/MD5 checksum: 613770 c6ddd70dd0106f140af204169becfba5 Size/MD5 checksum: 4800524 a942b7744fcd9b6f63807bcceff8874d Size/MD5 checksum: 348378 10e9927dc5f390afa7187abfb98c3f0b Size/MD5 checksum: 186922 296a46b37b5030d6e0223f14ea06e129 Size/MD5 checksum: 180776 7ab8cdac4f30e74eae7d3f0f9100b002 Size/MD5 checksum: 368036 35bbfee4582401a9703ee0ebe662c9c8 i386 architecture (Intel ia32) Size/MD5 checksum: 167228 3172d106b9d2a0b07704e5d54c759a09 Size/MD5 checksum: 177926 7fb0712c60c7fcedda0bd0072cda73a8 Size/MD5 checksum: 189320 b236d5aee0d1c56976086ee341769a97 Size/MD5 checksum: 333814 8edaaf6888ab48b74132da1ff9465199 Size/MD5 checksum: 614612 7ba6b7c533d94b2c8503d7b5a3af1ce6 Size/MD5 checksum: 277312 c0539ad7f6398157baa7edbcefa70f35 Size/MD5 checksum: 354808 f60ddea50db8aa7cd534c0453cd23d5a Size/MD5 checksum: 4288660 00b00a934c4e9452cfac1088e0226ddc Size/MD5 checksum: 183540 253aa290befff3621d773156b59c6c4e Size/MD5 checksum: 187642 cfedb34389b4dbcb6943a07b36a2d576 Size/MD5 checksum: 176284 34ea5de587476536d40e09bb2c4e5348 Size/MD5 checksum: 60744492357426f909eef72992b68cafd7a7e1 Size/MD5 checksum: 1422416 2647366c2c5e3f6ad7fc6973f0a2d761 ia64 architecture (Intel ia64) Size/MD5 checksum: 206266 59326303e8af22f4ea1161f9b7789490 Size/MD5 checksum: 186552 e1a3049a341bce026841fe7fa87e54ff Size/MD5 checksum: 1639402 b76d158dbbdd486607260c657ea79fff Size/MD5 checksum: 189152 72a5e78e4df438455535022a6e412f94 Size/MD5 checksum: 408536 ead410ed6db4f32c4659d0b9ffcf64a0 Size/MD5 checksum: 775540 358b6d4fe053b98891b4fd40673453a0 Size/MD5 checksum: 613788 48b321e0fc76d8d7811ce94d1551036c Size/MD5 checksum: 196006 276e02fe51cd553475d878365bc64aec Size/MD5 checksum: 378282 5b282caf341ddb5b187e3e809b66efb2 Size/MD5 checksum: 5097000 17f1d7e4e3afbd9d7dd57a11933999a5 Size/MD5 checksum: 306350 913e49427d99925aa122970763a71e3a Size/MD5 checksum: 171252 ba330738c66d9c70c336ac04cc8c239b Size/MD5 checksum: 200326 f5bf2d2f764367b2555ae5a9aac59b71 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 4608214 ee9465f9baba6fccb586842b80f8bc87 Size/MD5 checksum: 354398 1b93192720edc8b7666eb7a3ecfd8333 Size/MD5 checksum: 177702 3eeec0ccd96b8031622dff02785f4d93 Size/MD5 checksum: 180274 87f32086606c2d6649a3891996583f88 Size/MD5 checksum: 178648 f0efcca56299d5b52f0ae6416572aac7 Size/MD5 checksum: 345458 6cb66f3c9fa3f08e75d6d3ccf0d63eed Size/MD5 checksum: 167832 4fda26f6830bd1f1c55b4e6850617c52 Size/MD5 checksum: 187184 1fc7e6557d5c3be8eb1a5a8d4157466b Size/MD5 checksum: 277508 7c3d28499e55c67cd6dbbaffeb7837e8 Size/MD5 checksum: 612104 e181230855179d0a26e3f679f62940b7 Size/MD5 checksum: 613786 1282b8370864a3905101378bf3b50c93 Size/MD5 checksum: 192116 16f46f61a5a2ce6f9b7f90de2f8d174f Size/MD5 checksum: 1458256 f535b5734723f9be801e47551d444a25 powerpc architecture (PowerPC) Size/MD5 checksum: 1803982e0c4be889396b9385c1feca879b2d9a Size/MD5 checksum: 279904 6e6f874cee109cd4b7292ce4ec7d5e30 Size/MD5 checksum: 179232 c3086c1376ce9e8cfdb76f12fba853aa Size/MD5 checksum: 354008 6e8264271d78145b04e448095b4fc07b Size/MD5 checksum: 190166 9b6861834562ec4d051cb70cac515a1d Size/MD5 checksum: 613780 2d9267da4fcb86d6309aab0a6fe4545c Size/MD5 checksum: 337492 8cf24186b5cf77d331086bd28a334526 Size/MD5 checksum: 654184 9bf80f7ed225da053656289ad2b60111 Size/MD5 checksum: 169184 1fea38fb908d18c718f15b322fdad34a Size/MD5 checksum: 1475808 36e71297f5f7817d90352f468ab4ec61 Size/MD5 checksum: 4659520 748f57da738be243bc0d677ce10626af Size/MD5 checksum: 193378 8679ec821fbfb58376129ea9d239d840 Size/MD5 checksum: 184774 050f33fa11be53f0e5d521da8a384cac s390 architecture (IBM S/390) Size/MD5 checksum: 643548 fe587dde496d5edf6e76e89ec4196892 Size/MD5 checksum: 190032 5b161602145a8d1071a26b854062da6f Size/MD5 checksum: 179386 4fdb8d9be39664db65a9fb497e435f46 Size/MD5 checksum: 179236 07d12dd26dfad3f6410c1d089ef54758 Size/MD5 checksum: 353914 50d354b3c6f4672adf1a849ba9099288 Size/MD5 checksum: 613756 50c536fea2dadf65d405fa31ab27486f Size/MD5 checksum: 192634 9cd35f4035ed8bb3e7d22caa9185162b Size/MD5 checksum: 183302 cb2ebac90e7e19bbf541d57c80dc63c3 Size/MD5 checksum: 284736 a0f1197f0669f46899b998cb5d5f532e Size/MD5 checksum: 4724082 ef912c10e9dfe5c26654f56a531484d0 Size/MD5 checksum: 343822 c03e4a03c78a327179d11e3448d0701b Size/MD5 checksum: 168518 774e82a37790fee36636e8932e9fd3de Size/MD5 checksum: 1477014 5cd1f20f85c994243a90739e2a2e64a9 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 613762 b64d6b7dc60158b50e17e91c88e4029f Size/MD5 checksum: 167056 8ecef3bf04656b0a2a787624e724dd47 Size/MD5 checksum: 183458 69630d0d139aa4d5a91a57d2ea7a1c0a Size/MD5 checksum: 187562 ae149e9ee7bb6130e7e04369baa652fc Size/MD5 checksum: 1449106 a7d12df5c784c32a738c682b3e76336d Size/MD5 checksum: 4587008 e83347c13ea19c5bf233ecf7286f5459 Size/MD5 checksum: 177608 14f2fb006cfa5e05229b4412937c1f99 Size/MD5 checksum: 613916 75501a9a8621f20594c1d4b857b33c97 Size/MD5 checksum: 334628 f301f0cae78ba6f9feb214bc6255d311 Size/MD5 checksum: 276478 161332f46188063bbd8d76b4e67d4ea4 Size/MD5 checksum: 350068 1ba7be6ab648d17c1a921f9d2087f709 Size/MD5 checksum: 178422 bd57a7b4d1b0ddf227bc33834f1e5a7b Size/MD5 checksum: 188322 b28ec84a27653bc55692fe5c6b961a71 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-1460-1 addresses vulnerabilities in the PostgreSQL Database System, especially concerning local authentication and potential Denial of Service (DoS) risks. PostgreSQL Fixes, Debian Security, Credential Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 13, 2008 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here