Fwd: [GENERAL] PostgreSQL 7.2.2: Security Release

From: Lamar Owen (lamar.owenat_private)
Date: Fri Aug 23 2002 - 20:35:59 PDT

  • Next message: Matthew Murphy: "[Full-Disclosure] phpReactor - Cross-Site Scripting via STYLE"

    ----------  Forwarded Message  ----------
    
    Subject: [GENERAL] PostgreSQL 7.2.2: Security Release
    Date: Sat, 24 Aug 2002 00:22:17 -0300 (ADT)
    From: "Marc G. Fournier" <scrappyat_private>
    To: pgsql-announceat_private
    Cc: freebsd-databasesat_private, <pgsql-generalat_private>, Vince 
    Vielhaber <vevat_private>
    
    Due to recent security vulnerabilities reported on BugTraq, concerning
    several buffer overruns found in PostgreSQL, the PostgreSQL Global
    Development Team today released v7.2.2 of PostgreSQL that fixes these
    vulnerabilities.
    
    The following buffer overruns have been identified and addressed:
    
    		... in handling long datetime input
    		... in repeat()
    		... in lpad() and rpad() with multibyte
    		... in SET TIME ZONE and TZ env var
    
    Although v7.2.2 is a purely plug-n-play upgrade from v7.2.1, requiring no
    dump-n-reload of the database, it should be noted that these
    vulnerabilities are only critical on "open" or "shared" systems, as they
    require the ability to be able to connect to the database before they can
    be exploited.
    
    The latest release is available at:
    
    	ftp://ftp.postgresql.org/pub/sources/v7.2.2
    
    As well as at appropriate mirror sites.
    
    Please report any bugs/problems with this release to:
    
    		pgsql-bugsat_private
    
    Marc G. Fournier
    Co-ordinator
    PostgreSQL Global Development Group
    



    This archive was generated by hypermail 2b30 : Sat Aug 24 2002 - 11:05:11 PDT