Synopsis: Moderate: postgresql security update
Advisory ID: SLSA-2017:2728-1
Issue Date: 2017-09-14
CVE Numbers: CVE-2017-7546
CVE-2017-7547
—
The following packages have been upgraded to a later upstream version:
postgresql (9.2.23).
Security Fix(es):
* It was found that authenticating to a PostgreSQL database account with
an empty password was possible despite libpq’s refusal to send an empty
password. A remote attacker could potentially use this flaw to gain access
to database accounts with empty passwords. (CVE-2017-7546)
* An authorization flaw was found in the way PostgreSQL handled access to
the pg_user_mappings view on foreign servers. A remote, authenticated
attacker could potentially use this flaw to retrieve passwords from the
user mappings defined by the foreign server owners without actually having
the privileges to do so. (CVE-2017-7547)
—
SL7
x86_64
postgresql-debuginfo-9.2.23-1.el7_4.i686.rpm
postgresql-debuginfo-9.2.23-1.el7_4.x86_64.rpm
postgresql-libs-9.2.23-1.el7_4.i686.rpm
postgresql-libs-9.2.23-1.el7_4.x86_64.rpm
postgresql-9.2.23-1.el7_4.i686.rpm
postgresql-9.2.23-1.el7_4.x86_64.rpm
postgresql-contrib-9.2.23-1.el7_4.x86_64.rpm
postgresql-devel-9.2.23-1.el7_4.i686.rpm
postgresql-devel-9.2.23-1.el7_4.x86_64.rpm
postgresql-docs-9.2.23-1.el7_4.x86_64.rpm
postgresql-plperl-9.2.23-1.el7_4.x86_64.rpm
postgresql-plpython-9.2.23-1.el7_4.x86_64.rpm
postgresql-pltcl-9.2.23-1.el7_4.x86_64.rpm
postgresql-server-9.2.23-1.el7_4.x86_64.rpm
postgresql-static-9.2.23-1.el7_4.i686.rpm
postgresql-static-9.2.23-1.el7_4.x86_64.rpm
postgresql-test-9.2.23-1.el7_4.x86_64.rpm
postgresql-upgrade-9.2.23-1.el7_4.x86_64.rpm
– Scientific Linux Development Team