Lists: | pgsql-announcepgsql-general |
---|
From: | "Marc G(dot) Fournier" <scrappy(at)postgresql(dot)org> |
---|---|
To: | pgsql-announce(at)postgresql(dot)org |
Cc: | pgsql-general(at)postgresql(dot)org |
Subject: | PostgreSQL Security Release(s) for 7.2, 7.3 and 7.4 |
Date: | 2004-10-23 14:14:34 |
Message-ID: | 20041023110218.K16873@ganymede.hub.org |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Lists: | pgsql-announce pgsql-general |
In order to address a recent security report from iDefence, we have
released 3 new "point" releases: 7.2.6, 7.3.8 and 7.4.6
Although rated only a Medium risk, according to their web site: "A
vulnerability exists due to the insecure creation of temporary files,
which could possibly let a malicious user overwrite arbitrary files."
Also in these releases is a potential 'data loss' bug that was recently
identified:
* Repair possible failure to update hint bits on disk
Under rare circumstances this oversight could lead to "could not
access transaction status" failures, which qualifies it as a
potential-data-loss bug.
Although not yet available via Bittorrent, these releases are available
through ftp at all of the mirrors, and Devrim is currently working on RPMs
for the various releases, which should be available soon.
For a listing of all currently available FTP mirrors, please see:
http://www.postgresql.org/mirrors-ftp.html
----
Marc G. Fournier Hub.Org Networking Services (http://www.hub.org)
Email: scrappy(at)hub(dot)org Yahoo!: yscrappy ICQ: 7615664
From: | Neil Conway <neilc(at)samurai(dot)com> |
---|---|
To: | "Marc G(dot) Fournier" <scrappy(at)postgresql(dot)org> |
Cc: | pgsql-general(at)postgresql(dot)org |
Subject: | Re: PostgreSQL Security Release(s) for 7.2, 7.3 and 7.4 |
Date: | 2004-10-24 07:19:42 |
Message-ID: | 417B578E.2000308@samurai.com |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Lists: | pgsql-announce pgsql-general |
Marc G. Fournier wrote:
> In order to address a recent security report from iDefence, we have
> released 3 new "point" releases: 7.2.6, 7.3.8 and 7.4.6
Assuming you're referring to the make_oidjoins_check bug, I don't think
it is accurate to bill these as "security releases". As the 7.4.6
release notes plainly state:
---
# Avoid using temp files in /tmp in make_oidjoins_check
This has been reported as a security issue, though it's hardly worthy of
concern since there is no reason for non-developers to use this script
anyway.
---
That said, the fix for the clog bug is reason enough to make the point
releases, and reason enough for users to upgrade.
-Neil
From: | Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> |
---|---|
To: | Neil Conway <neilc(at)samurai(dot)com> |
Cc: | "Marc G(dot) Fournier" <scrappy(at)postgresql(dot)org>, pgsql-general(at)postgresql(dot)org |
Subject: | Re: PostgreSQL Security Release(s) for 7.2, 7.3 and 7.4 |
Date: | 2004-10-24 14:43:14 |
Message-ID: | 8466.1098628994@sss.pgh.pa.us |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Lists: | pgsql-announce pgsql-general |
Neil Conway <neilc(at)samurai(dot)com> writes:
> Marc G. Fournier wrote:
>> In order to address a recent security report from iDefence, we have
>> released 3 new "point" releases: 7.2.6, 7.3.8 and 7.4.6
> Assuming you're referring to the make_oidjoins_check bug,
He's not. There were two other recent security reports, which core kept
to ourselves until the release could be made. The other issues were
only marginally more serious than make_oidjoins_check, but worth fixing
now given that the hint-bit bug was forcing a release anyway.
regards, tom lane
From: | Neil Conway <neilc(at)samurai(dot)com> |
---|---|
To: | Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> |
Cc: | "Marc G(dot) Fournier" <scrappy(at)postgresql(dot)org>, pgsql-general <pgsql-general(at)postgresql(dot)org> |
Subject: | Re: PostgreSQL Security Release(s) for 7.2, 7.3 and 7.4 |
Date: | 2004-10-24 23:46:52 |
Message-ID: | 1098661612.12577.28.camel@localhost.localdomain |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Lists: | pgsql-announce pgsql-general |
On Mon, 2004-10-25 at 00:43, Tom Lane wrote:
> He's not. There were two other recent security reports, which core kept
> to ourselves until the release could be made.
Ah, ok -- fair enough. Are those additional security fixes mentioned in
the release notes?
-Neil
From: | Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> |
---|---|
To: | Neil Conway <neilc(at)samurai(dot)com> |
Cc: | "Marc G(dot) Fournier" <scrappy(at)postgresql(dot)org>, pgsql-general <pgsql-general(at)postgresql(dot)org> |
Subject: | Re: PostgreSQL Security Release(s) for 7.2, 7.3 and 7.4 |
Date: | 2004-10-24 23:53:58 |
Message-ID: | 28630.1098662038@sss.pgh.pa.us |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Lists: | pgsql-announce pgsql-general |
Neil Conway <neilc(at)samurai(dot)com> writes:
> On Mon, 2004-10-25 at 00:43, Tom Lane wrote:
>> He's not. There were two other recent security reports, which core kept
>> to ourselves until the release could be made.
> Ah, ok -- fair enough. Are those additional security fixes mentioned in
> the release notes?
Yes, or at least the one that affected PG proper (pg_ctl as root).
The other was a bug in the RPM init script.
I just realized that Devrim wasn't in the loop on that, so he'll
probably have to rebuild the PGDG RPMs :-(
regards, tom lane