The regression of postgresql-9.6-postgis-2.3-scripts being empty in 2.3.1+dfsg-2+deb9u1 has been fixed. For Debian 9 stretch, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2857-2
In PostGIS, which adds support for geographic objects to the PostgreSQL database, denial of service via crafted ST_AsX3D function input was fixed. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2857-1
It was found that the function ST_AsX3D in PostGIS, a module that adds spatial objects to the PostgreSQL object-relational database, did not handle empty values properly, allowing malicious users to cause denial of service or possibly other unspecified behaviour. . Package : postgis Version : 2.1.4+dfsg-3+deb8u1 CVE ID : CVE-2017-18359 It was found that the function ST_AsX3D in PostGIS, a module that adds spatial objects to the PostgreSQL object-relational database, did not handle empty values properly, allowing malicious users to cause denial of service or possibly other unspecified behaviour. For Debian 8 "Jessie", this problem has been fixed in version 2.1.4+dfsg-3+deb8u1. We recommend that you upgrade your postgis packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Package : postgis Version : 2.1.4+dfsg-3+deb8u1 CVE ID : CVE-2017-18359 It was found that the functi. found, function, st_asx3d, postgis, module, spatial, objects, postgr. . Severity: Critical. LinuxSecurity.com Team
Update to latest release, which includes security fixes. Update to 2.1.6, per changes described at: enable json-c for postigs, but disable it for upgrade part Rebuild for Proj 4.9.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-5575 2015-04-05 11:03:00 -------------------------------------------------------------------------------- Name : postgis Product : Fedora 21 Version : 2.1.7 Release : 1.fc21 URL : http://www.refractions.net/products/postgis/ Summary : Geographic Information Systems Extensions to PostgreSQL Description : PostGIS adds support for geographic objects to the PostgreSQL object-relational database. In effect, PostGIS "spatially enables" the PostgreSQL server, allowing it to be used as a backend spatial database for geographic information systems (GIS), much like ESRI's SDE or Oracle's Spatial extension. PostGIS follows the OpenGIS "Simple Features Specification for SQL" and has been certified as compliant with the "Types and Functions" profile. -------------------------------------------------------------------------------- Update Information: Update to latest release, which includes security fixes. Update to 2.1.6, per changes described at: enable json-c for postigs, but disable it for upgrade part Rebuild for Proj 4.9.1 -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 1 2015 Devrim Gündüz - 2.1.7-1 - Update to 2.1.7, per changes described at: * Fri Mar 27 2015 Devrim Gündüz - 2.1.6-1 - Update to 2.1.6, per changes described at: * Thu Jan 8 2015 Jozef Mlich - 2.1.5-2 - disable json-c/geojson just for upgrade part of postgis * Mon Dec 22 2014 Devrim Gündüz - 2.1.5-1 - Update to 2.1.5, per changes described at: and -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update postgis' at thecommand line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.