MGASA-2016-0085

Source
https://advisories.mageia.org/MGASA-2016-0085.html
Import Source
https://advisories.mageia.org/MGASA-2016-0085.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2016-0085
Related
Published
2016-03-02T18:28:46Z
Modified
2016-03-02T18:19:22Z
Summary
Updated postgresql packages fix security vulnerabilities
Details

Updated postgresql packages fix security vulnerabilities:

PostgreSQL 9.3.x before 9.3.11 and 9.4.x before 9.4.6 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privileges via unspecified vectors (CVE-2016-0766).

PostgreSQL 9.3.x before 9.3.11 and 9.4.x before 9.4.6 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regular expression (CVE-2016-0773).

References
Credits

Affected packages

Mageia:5 / postgresql9.3

Package

Name
postgresql9.3
Purl
pkg:rpm/mageia/postgresql9.3?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.3.11-1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / postgresql9.4

Package

Name
postgresql9.4
Purl
pkg:rpm/mageia/postgresql9.4?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.4.6-1.mga5

Ecosystem specific

{
    "section": "core"
}