MGASA-2017-0230
Dashboard / Vulnerabilities / MGASA-2017-0230
MGASA-2017-0230
Summary: Updated postgresql9.4 packages fix security vulnerabilities
Details: Robert Haas discovered that some selectivity estimators did not validate user privileges which could result in information disclosure (CVE-2017-7484). Daniel Gustafsson discovered that the PGREQUIRESSL environment variable did no longer enforce a TLS connection (CVE-2017-7485). Andrew Wheelwright discovered that user mappings were insufficiently restricted (CVE-2017-7486).
References: https://advisories.mageia.org/MGASA-2017-0230.html, https://bugs.mageia.org/show_bug.cgi?id=20842, http://www.postgresql.org/docs/current/static/release-9-3-17.html, http://www.postgresql.org/docs/current/static/release-9-4-12.html, https://www.postgresql.org/about/news/1746/
Affected packages
Package
Name: postgresql9.3
Purl: pkg:rpm/mageia/postgresql9.3?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
