postgresql-9.1 9.1.5-1 source package in Ubuntu

Changelog

postgresql-9.1 (9.1.5-1) unstable; urgency=medium


  * Urgency medium due to security fixes and bug fixes which should reach
    Wheezy quickly.
  * New upstream bug fix/security release:
    - Prevent access to external files/URLs via XML entity references.
      xml_parse() would attempt to fetch external files or URLs as needed
      to resolve DTD and entity references in an XML value, thus allowing
      unprivileged database users to attempt to fetch data with the
      privileges of the database server. While the external data wouldn't
      get returned directly to the user, portions of it could be exposed
      in error messages if the data didn't parse as valid XML; and in any
      case the mere ability to check existence of a file might be useful
      to an attacker. (CVE-2012-3489)
    - Prevent access to external files/URLs via "contrib/xml2"'s
      xslt_process().
      libxslt offers the ability to read and write both files and URLs
      through stylesheet commands, thus allowing unprivileged database
      users to both read and write data with the privileges of the
      database server. Disable that through proper use of libxslt's
      security options. (CVE-2012-3488)
      Also, remove xslt_process()'s ability to fetch documents and
      stylesheets from external files/URLs. While this was a documented
      "feature", it was long regarded as a bad idea. The fix for
      CVE-2012-3489 broke that capability, and rather than expend effort
      on trying to fix it, we're just going to summarily remove it.
    - Lots of other bug fixes, see HISTORY/changelog.gz.

 -- Martin Pitt <email address hidden>  Fri, 17 Aug 2012 14:41:52 +0200

Upload details

Uploaded by:
Debian PostgreSQL Maintainers
Uploaded to:
Sid
Original maintainer:
Debian PostgreSQL Maintainers
Architectures:
any all
Section:
database
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
postgresql-9.1_9.1.5-1.dsc 3.2 KiB 9f7aba30e5f0aafd58035656d015b79471bacc1033bb518102078ad4b2fd92a2
postgresql-9.1_9.1.5.orig.tar.bz2 14.9 MiB 0b889c132426fc68d8c2eb1bf112bf99cc653e9c95b5f4bbebc55cd9a8d6ce44
postgresql-9.1_9.1.5-1.debian.tar.gz 32.8 KiB 5989b1dae6525ed1c47f7400fa71abb3de5c5fb893a63ff92e6d469a7e66f934

Available diffs

No changes file available.

Binary packages built by this source

libecpg-compat3: No summary available for libecpg-compat3 in ubuntu quantal.

No description available for libecpg-compat3 in ubuntu quantal.

libecpg-dev: No summary available for libecpg-dev in ubuntu quantal.

No description available for libecpg-dev in ubuntu quantal.

libecpg6: No summary available for libecpg6 in ubuntu quantal.

No description available for libecpg6 in ubuntu quantal.

libpgtypes3: No summary available for libpgtypes3 in ubuntu quantal.

No description available for libpgtypes3 in ubuntu quantal.

libpq-dev: No summary available for libpq-dev in ubuntu quantal.

No description available for libpq-dev in ubuntu quantal.

libpq5: No summary available for libpq5 in ubuntu quantal.

No description available for libpq5 in ubuntu quantal.

postgresql-9.1: No summary available for postgresql-9.1 in ubuntu quantal.

No description available for postgresql-9.1 in ubuntu quantal.

postgresql-9.1-dbg: No summary available for postgresql-9.1-dbg in ubuntu quantal.

No description available for postgresql-9.1-dbg in ubuntu quantal.

postgresql-client-9.1: No summary available for postgresql-client-9.1 in ubuntu quantal.

No description available for postgresql-client-9.1 in ubuntu quantal.

postgresql-contrib-9.1: No summary available for postgresql-contrib-9.1 in ubuntu quantal.

No description available for postgresql-contrib-9.1 in ubuntu quantal.

postgresql-doc-9.1: No summary available for postgresql-doc-9.1 in ubuntu quantal.

No description available for postgresql-doc-9.1 in ubuntu quantal.

postgresql-plperl-9.1: No summary available for postgresql-plperl-9.1 in ubuntu quantal.

No description available for postgresql-plperl-9.1 in ubuntu quantal.

postgresql-plpython-9.1: No summary available for postgresql-plpython-9.1 in ubuntu quantal.

No description available for postgresql-plpython-9.1 in ubuntu quantal.

postgresql-plpython3-9.1: No summary available for postgresql-plpython3-9.1 in ubuntu quantal.

No description available for postgresql-plpython3-9.1 in ubuntu quantal.

postgresql-pltcl-9.1: No summary available for postgresql-pltcl-9.1 in ubuntu quantal.

No description available for postgresql-pltcl-9.1 in ubuntu quantal.

postgresql-server-dev-9.1: No summary available for postgresql-server-dev-9.1 in ubuntu quantal.

No description available for postgresql-server-dev-9.1 in ubuntu quantal.