Lucene search

K
osvGoogleOSV:DSA-3475-1
HistoryFeb 13, 2016 - 12:00 a.m.

postgresql-9.1 - security update

2016-02-1300:00:00
Google
osv.dev
13

0.211 Low

EPSS

Percentile

96.4%

Several vulnerabilities have been found in PostgreSQL-9.1, a SQL
database system.

  • CVE-2015-5288
    Josh Kupershmidt discovered a vulnerability in the crypt() function
    in the pgCrypto extension. Certain invalid salt arguments can cause
    the server to crash or to disclose a few bytes of server memory.
  • CVE-2016-0766
    A privilege escalation vulnerability for users of PL/Java was
    discovered. Certain custom configuration settings (GUCs) for PL/Java
    will now be modifiable only by the database superuser to mitigate
    this issue.
  • CVE-2016-0773
    Tom Lane and Greg Stark discovered a flaw in the way PostgreSQL
    processes specially crafted regular expressions. Very large
    character ranges in bracket expressions could cause infinite
    loops or memory overwrites. A remote attacker can exploit this
    flaw to cause a denial of service or, potentially, to execute
    arbitrary code.

For the oldstable distribution (wheezy), these problems have been fixed
in version 9.1.20-0+deb7u1.

We recommend that you upgrade your postgresql-9.1 packages.