Revised Security Release available for 8.2, 8.1, 8.0

From: josh(at)postgresql(dot)org
To: pgsql-announce(at)postgresql(dot)org
Subject: Revised Security Release available for 8.2, 8.1, 8.0
Date: 2007-02-07 19:09:21
Message-ID: 20070207190921.quq3gkb6ogocgsc0@webmail.postgresql.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-announce

Revised Security Release available for 8.2, 8.1, 8.0

The PostgreSQL Global Development Group releases today a security update for
all PostgreSQL 8.X versions: minor versions 8.2.3, 8.1.8, 8.0.12. This
release replaces the security release from February 5th, which contained a
type-casting bug affecting many users.

If you downloaded a copy of 8.2.2, 8.1.7 or 8.0.11, you should discard that
versions and install the updated versions instead.

This release fixes CVE-2007-0555 and CVE-2007-0556. Both of these issues
allow an authenticated attacker with the permissions to run arbitrary SQL to
launch a denial-of-service attack or possibly read out random chunks of
memory. Since attacks to require authenticated access, the security hole is
only considered medium risk. You can read more about the issues on Mitre:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0555
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0556

The new minor versions may be downloaded from our download page:
http://www.postgresql.org/download/. Users will not need to dump & reload
for the upgrade. However, see the release notes for your target version:
http://www.postgresql.org/docs/8.2/static/release.html

Browse pgsql-announce by date

  From Date Subject
Next Message Devrim GUNDUZ 2007-02-08 15:50:59 [Security] New RPM Sets for Fedora Core / Red Hat Enterprise Linux
Previous Message Selena Deckelmann 2007-02-06 23:32:39 Fwd: [ANNOUNCE] Warning: WAIT before applying 8.1, 8.2 security releases!