postgresql-9.1 9.1.5-1 source package in Ubuntu
Changelog
postgresql-9.1 (9.1.5-1) unstable; urgency=medium * Urgency medium due to security fixes and bug fixes which should reach Wheezy quickly. * New upstream bug fix/security release: - Prevent access to external files/URLs via XML entity references. xml_parse() would attempt to fetch external files or URLs as needed to resolve DTD and entity references in an XML value, thus allowing unprivileged database users to attempt to fetch data with the privileges of the database server. While the external data wouldn't get returned directly to the user, portions of it could be exposed in error messages if the data didn't parse as valid XML; and in any case the mere ability to check existence of a file might be useful to an attacker. (CVE-2012-3489) - Prevent access to external files/URLs via "contrib/xml2"'s xslt_process(). libxslt offers the ability to read and write both files and URLs through stylesheet commands, thus allowing unprivileged database users to both read and write data with the privileges of the database server. Disable that through proper use of libxslt's security options. (CVE-2012-3488) Also, remove xslt_process()'s ability to fetch documents and stylesheets from external files/URLs. While this was a documented "feature", it was long regarded as a bad idea. The fix for CVE-2012-3489 broke that capability, and rather than expend effort on trying to fix it, we're just going to summarily remove it. - Lots of other bug fixes, see HISTORY/changelog.gz. -- Martin Pitt <email address hidden> Fri, 17 Aug 2012 14:41:52 +0200
Upload details
- Uploaded by:
- Debian PostgreSQL Maintainers
- Uploaded to:
- Sid
- Original maintainer:
- Debian PostgreSQL Maintainers
- Architectures:
- any all
- Section:
- database
- Urgency:
- Medium Urgency
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
postgresql-9.1_9.1.5-1.dsc | 3.2 KiB | 9f7aba30e5f0aafd58035656d015b79471bacc1033bb518102078ad4b2fd92a2 |
postgresql-9.1_9.1.5.orig.tar.bz2 | 14.9 MiB | 0b889c132426fc68d8c2eb1bf112bf99cc653e9c95b5f4bbebc55cd9a8d6ce44 |
postgresql-9.1_9.1.5-1.debian.tar.gz | 32.8 KiB | 5989b1dae6525ed1c47f7400fa71abb3de5c5fb893a63ff92e6d469a7e66f934 |
Available diffs
- diff from 9.1.4-3 to 9.1.5-1 (741.1 KiB)
No changes file available.
Binary packages built by this source
- libecpg-compat3: No summary available for libecpg-compat3 in ubuntu quantal.
No description available for libecpg-compat3 in ubuntu quantal.
- libecpg-dev: No summary available for libecpg-dev in ubuntu quantal.
No description available for libecpg-dev in ubuntu quantal.
- libecpg6: No summary available for libecpg6 in ubuntu quantal.
No description available for libecpg6 in ubuntu quantal.
- libpgtypes3: No summary available for libpgtypes3 in ubuntu quantal.
No description available for libpgtypes3 in ubuntu quantal.
- libpq-dev: No summary available for libpq-dev in ubuntu quantal.
No description available for libpq-dev in ubuntu quantal.
- libpq5: No summary available for libpq5 in ubuntu quantal.
No description available for libpq5 in ubuntu quantal.
- postgresql-9.1: No summary available for postgresql-9.1 in ubuntu quantal.
No description available for postgresql-9.1 in ubuntu quantal.
- postgresql-9.1-dbg: No summary available for postgresql-9.1-dbg in ubuntu quantal.
No description available for postgresql-9.1-dbg in ubuntu quantal.
- postgresql-client-9.1: No summary available for postgresql-client-9.1 in ubuntu quantal.
No description available for postgresql-
client- 9.1 in ubuntu quantal.
- postgresql-contrib-9.1: No summary available for postgresql-contrib-9.1 in ubuntu quantal.
No description available for postgresql-
contrib- 9.1 in ubuntu quantal.
- postgresql-doc-9.1: No summary available for postgresql-doc-9.1 in ubuntu quantal.
No description available for postgresql-doc-9.1 in ubuntu quantal.
- postgresql-plperl-9.1: No summary available for postgresql-plperl-9.1 in ubuntu quantal.
No description available for postgresql-
plperl- 9.1 in ubuntu quantal.
- postgresql-plpython-9.1: No summary available for postgresql-plpython-9.1 in ubuntu quantal.
No description available for postgresql-
plpython- 9.1 in ubuntu quantal.
- postgresql-plpython3-9.1: No summary available for postgresql-plpython3-9.1 in ubuntu quantal.
No description available for postgresql-
plpython3- 9.1 in ubuntu quantal.
- postgresql-pltcl-9.1: No summary available for postgresql-pltcl-9.1 in ubuntu quantal.
No description available for postgresql-
pltcl-9. 1 in ubuntu quantal.
- postgresql-server-dev-9.1: No summary available for postgresql-server-dev-9.1 in ubuntu quantal.
No description available for postgresql-
server- dev-9.1 in ubuntu quantal.