Fedora 7 : postgresql-8.2.6-1.fc7 (2008-0552)

high Nessus Plugin ID 29948

Synopsis

The remote Fedora host is missing a security update.

Description

- Mon Jan 7 2008 Tom Lane <tgl at redhat.com> 8.2.6-1

- Update to PostgreSQL 8.2.6 to fix CVE-2007-4769, CVE-2007-4772, CVE-2007-6067, CVE-2007-6600, CVE-2007-6601

- Make initscript and pam config files be installed unconditionally; seems new buildroots don't necessarily have those directories in place

- Thu Sep 20 2007 Tom Lane <tgl at redhat.com> 8.2.5-1

- Update to PostgreSQL 8.2.5 and pgtcl 1.6.0

- Fix multilib problem for /usr/include/ecpg_config.h (which is new in 8.2.x)

- Use tzdata package's data files instead of private copy, so that postgresql-server need not be turned for routine timezone updates

- Don't remove postgres user/group during RPM uninstall, per Fedora packaging guidelines

- Recent perl changes in rawhide mean we need a more specific BuildRequires

- Wed Jun 20 2007 Tom Lane <tgl at redhat.com> 8.2.4-2

- Fix oversight in postgresql-test makefile: pg_regress isn't a shell script anymore. Per upstream bug 3398.

- Tue Apr 24 2007 Tom Lane <tgl at redhat.com> 8.2.4-1

- Update to PostgreSQL 8.2.4 for CVE-2007-2138, data loss bugs Resolves: #237682

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected packages.

See Also

https://bugzilla.redhat.com/show_bug.cgi?id=315231

https://bugzilla.redhat.com/show_bug.cgi?id=316511

https://bugzilla.redhat.com/show_bug.cgi?id=400931

https://bugzilla.redhat.com/show_bug.cgi?id=427127

https://bugzilla.redhat.com/show_bug.cgi?id=427128

https://bugzilla.redhat.com/show_bug.cgi?id=427772

http://www.nessus.org/u?b94a6f53

Plugin Details

Severity: High

ID: 29948

File Name: fedora_2008-0552.nasl

Version: 1.18

Type: local

Agent: unix

Published: 1/14/2008

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:postgresql, p-cpe:/a:fedoraproject:fedora:postgresql-contrib, p-cpe:/a:fedoraproject:fedora:postgresql-debuginfo, p-cpe:/a:fedoraproject:fedora:postgresql-devel, p-cpe:/a:fedoraproject:fedora:postgresql-docs, p-cpe:/a:fedoraproject:fedora:postgresql-libs, p-cpe:/a:fedoraproject:fedora:postgresql-plperl, p-cpe:/a:fedoraproject:fedora:postgresql-plpython, p-cpe:/a:fedoraproject:fedora:postgresql-pltcl, p-cpe:/a:fedoraproject:fedora:postgresql-python, p-cpe:/a:fedoraproject:fedora:postgresql-server, p-cpe:/a:fedoraproject:fedora:postgresql-tcl, p-cpe:/a:fedoraproject:fedora:postgresql-test, cpe:/o:fedoraproject:fedora:7

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 1/11/2008

Reference Information

CVE: CVE-2007-4769, CVE-2007-4772, CVE-2007-6067, CVE-2007-6600, CVE-2007-6601

BID: 27163

CWE: 189, 264, 287, 399

FEDORA: 2008-0552