MGASA-2017-0230

Source
https://advisories.mageia.org/MGASA-2017-0230.html
Import Source
https://advisories.mageia.org/MGASA-2017-0230.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2017-0230
Related
Published
2017-07-30T15:58:51Z
Modified
2017-07-30T15:40:01Z
Summary
Updated postgresql9.4 packages fix security vulnerabilities
Details

Robert Haas discovered that some selectivity estimators did not validate user privileges which could result in information disclosure (CVE-2017-7484).

Daniel Gustafsson discovered that the PGREQUIRESSL environment variable did no longer enforce a TLS connection (CVE-2017-7485).

Andrew Wheelwright discovered that user mappings were insufficiently restricted (CVE-2017-7486).

References
Credits

Affected packages

Mageia:5 / postgresql9.3

Package

Name
postgresql9.3
Purl
pkg:rpm/mageia/postgresql9.3?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.3.17-1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / postgresql9.4

Package

Name
postgresql9.4
Purl
pkg:rpm/mageia/postgresql9.4?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.4.12-1.mga5

Ecosystem specific

{
    "section": "core"
}