Lucene search

K
osvGoogleOSV:DSA-3270-1
HistoryMay 22, 2015 - 12:00 a.m.

postgresql-9.4 - security update

2015-05-2200:00:00
Google
osv.dev
6

0.085 Low

EPSS

Percentile

94.5%

Several vulnerabilities have been found in PostgreSQL-9.4, a SQL
database system.

SSL clients disconnecting just before the authentication timeout
expires can cause the server to crash.

The replacement implementation of snprintf() failed to check for
errors reported by the underlying system library calls; the main
case that might be missed is out-of-memory situations. In the worst
case this might lead to information exposure.

In contrib/pgcrypto, some cases of decryption with an incorrect key
could report other error message texts. Fix by using a
one-size-fits-all message.

For the stable distribution (jessie), these problems have been fixed in
version 9.4.2-0+deb8u1.

For the testing distribution (stretch), these problems will be fixed
soon.

For the unstable distribution (sid), these problems have been fixed in
version 9.4.2-1.

We recommend that you upgrade your postgresql-9.4 packages.

CPENameOperatorVersion
postgresql-9.4eq9.4.1-1