MGASA-2016-0085
Dashboard / Vulnerabilities / MGASA-2016-0085
Summary: Updated postgresql packages fix security vulnerabilities
Details: Updated postgresql packages fix security vulnerabilities: PostgreSQL 9.3.x before 9.3.11 and 9.4.x before 9.4.6 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privileges via unspecified vectors (CVE-2016-0766). PostgreSQL 9.3.x before 9.3.11 and 9.4.x before 9.4.6 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regular expression (CVE-2016-0773).
References: https://advisories.mageia.org/MGASA-2016-0085.html, https://bugs.mageia.org/show_bug.cgi?id=17744, http://www.ubuntu.com/usn/usn-2894-1/
Affected packages
Package
Name: postgresql9.3
Purl: pkg:rpm/mageia/postgresql9.3?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
