postgresql-8.4.20-8.AXS4

エラータID: AXSA:2017-2312:02

Release date: 
Tuesday, October 10, 2017 - 02:42
Subject: 
postgresql-8.4.20-8.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
Moderate
Description: 

PostgreSQL is an advanced object-relational database management system (DBMS).

Security Fix(es):

* It was found that authenticating to a PostgreSQL database account with an empty password was possible despite libpq's refusal to send an empty password. A remote attacker could potentially use this flaw to gain access to database accounts with empty passwords. (CVE-2017-7546)

Asianux would like to thank the PostgreSQL project for reporting this issue.
Upstream acknowledges Ben de Graaff, Jelte Fennema, and Jeroen van der Ham as
the original reporters.

CVE-2017-7546
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are
vulnerable to incorrect authentication flaw allowing remote attackers
to gain access to database accounts with an empty password.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. postgresql-8.4.20-8.AXS4.src.rpm
    MD5: 984294bde36014965c8b2a0b9cfcf311
    SHA-256: 7a845ad2485cccc3df5cdd3e4eaf34b127fe79fb86d00c806cbb13fca5fab979
    Size: 20.60 MB

Asianux Server 4 for x86
  1. postgresql-8.4.20-8.AXS4.i686.rpm
    MD5: cb77d61605a6580f2cf5d70ac8992b64
    SHA-256: f8a7e8ea75a8afa5f7774dbc298a0cb6aa8e9bc4895501b525b7ec89b1833c74
    Size: 2.58 MB
  2. postgresql-contrib-8.4.20-8.AXS4.i686.rpm
    MD5: d28c6bafbee3888d36cb32fcee65fcce
    SHA-256: 8e6549872f6db9362cb2a1f40a328451b6327db4ea27e82ae6ed725a06e6a754
    Size: 350.21 kB
  3. postgresql-devel-8.4.20-8.AXS4.i686.rpm
    MD5: 610897865eff28d5c1c77c9a7708f639
    SHA-256: 9fb9ca16fa89422e643735288b1526007df79fe826ac13de5244c869ec51a596
    Size: 810.62 kB
  4. postgresql-docs-8.4.20-8.AXS4.i686.rpm
    MD5: b0be403ef9fe7be0895526667bc7018e
    SHA-256: 9f95cf8b5785b2abdf235cc832fb790579c7892703d01da087b0e47e5a57987f
    Size: 6.95 MB
  5. postgresql-libs-8.4.20-8.AXS4.i686.rpm
    MD5: a11b62fb3c404f927ebad72a955fa6ad
    SHA-256: 64714bdd015bdb019fd8cc71bc0759962bc1aa4b8228f62e20ec677055ad98cc
    Size: 205.14 kB
  6. postgresql-plperl-8.4.20-8.AXS4.i686.rpm
    MD5: a48308465ff599a4723629ab133a9fba
    SHA-256: c72abf187feea30ac5c3e18dbab19acbc07de5e7bed58bc8210479ec79ce5b04
    Size: 57.14 kB
  7. postgresql-plpython-8.4.20-8.AXS4.i686.rpm
    MD5: 040020ede6b374fd885d29b50f91bb94
    SHA-256: 2f47f15c2ba66429cbd8593021679d53a5e929898ae9b56882fd788c2d31558e
    Size: 57.82 kB
  8. postgresql-pltcl-8.4.20-8.AXS4.i686.rpm
    MD5: e2cba57c29abff3c680fe58fdf970f7e
    SHA-256: 6d74e2641a7715af859bf7af2a43c85f547fef244cad43a0bd7709197eb29af2
    Size: 46.07 kB
  9. postgresql-server-8.4.20-8.AXS4.i686.rpm
    MD5: b47ff02b10f91805813164bc253806f6
    SHA-256: bdf71bb1332bfe80370e3f8868e5bc9d26df50fd1d280eb35621bf6501e40357
    Size: 3.40 MB
  10. postgresql-test-8.4.20-8.AXS4.i686.rpm
    MD5: a922458a32116b4be5e81c007ab52ae4
    SHA-256: 8142afd02a37aeec58db7114c16f5da1993b8df68fe307bbb57a84b69689d0e4
    Size: 1.11 MB

Asianux Server 4 for x86_64
  1. postgresql-8.4.20-8.AXS4.x86_64.rpm
    MD5: 414949cebbf3936330439374683ff74c
    SHA-256: 3b0a257864a109dbf667895229f0a57d515b78f101ca2ba3ba06ef5120bc26a6
    Size: 2.59 MB
  2. postgresql-contrib-8.4.20-8.AXS4.x86_64.rpm
    MD5: d0da7ad45e6a1b222d249a9a396d6182
    SHA-256: 550a892d8cb9f9c04e02b81988b68cc084d77a6b5c0955580481663d6ea10ad1
    Size: 353.63 kB
  3. postgresql-devel-8.4.20-8.AXS4.x86_64.rpm
    MD5: 47db5504dc0ada2e28b9441934bcad23
    SHA-256: 14669a0dbc7fe8929a4e3bbdd6002f74c5970f1ca7361054a9569216ace69819
    Size: 815.25 kB
  4. postgresql-docs-8.4.20-8.AXS4.x86_64.rpm
    MD5: b8a52ae0cacec7072a3ee5e7a5e3f1d6
    SHA-256: c2d98dcea4eca89903a7f27d1fa3ffd9426a80aecfc92c3cea78fa84e9612067
    Size: 6.95 MB
  5. postgresql-libs-8.4.20-8.AXS4.x86_64.rpm
    MD5: 52987237fb5e25df2c288c8e5015caeb
    SHA-256: 6291935fb5f59e8bff32a64ce25cdd41fc26adb7b0d16c31092d15a70889134f
    Size: 201.25 kB
  6. postgresql-plperl-8.4.20-8.AXS4.x86_64.rpm
    MD5: 64a62cc3d53ff8080509f9d1c2f9cc3c
    SHA-256: 363a213b029097816a02e6d981d13ba08a30a90aef5bed9c42ed2d79ac47f477
    Size: 56.92 kB
  7. postgresql-plpython-8.4.20-8.AXS4.x86_64.rpm
    MD5: 9831273f80984228540d14e38fd72cc8
    SHA-256: b1de1a2c5cdafe8d1cc3385a2e9ef13e4d00e7094d720f5faabe42c2ee348373
    Size: 58.55 kB
  8. postgresql-pltcl-8.4.20-8.AXS4.x86_64.rpm
    MD5: dd56b5022b884f2c30efb9ecc6f2d73e
    SHA-256: b9651e02035a21ce9a9a8762c9385173a61744609d8cd60fb5003b622ab9819f
    Size: 45.84 kB
  9. postgresql-server-8.4.20-8.AXS4.x86_64.rpm
    MD5: bebb2619e8d75b2329fcae373a74bf00
    SHA-256: 0fdd69314bbb3fc7a6cec741d909cc261085002c67a2ed375f5169c666893335
    Size: 3.44 MB
  10. postgresql-test-8.4.20-8.AXS4.x86_64.rpm
    MD5: f98b4a1da2e37e120c10fb233f806743
    SHA-256: 63023d0b9d33eb789562a9577308695e3c0d7ca7f9dcea1ceec0fffc14aa285e
    Size: 1.11 MB
  11. postgresql-8.4.20-8.AXS4.i686.rpm
    MD5: cb77d61605a6580f2cf5d70ac8992b64
    SHA-256: f8a7e8ea75a8afa5f7774dbc298a0cb6aa8e9bc4895501b525b7ec89b1833c74
    Size: 2.58 MB
  12. postgresql-devel-8.4.20-8.AXS4.i686.rpm
    MD5: 610897865eff28d5c1c77c9a7708f639
    SHA-256: 9fb9ca16fa89422e643735288b1526007df79fe826ac13de5244c869ec51a596
    Size: 810.62 kB
  13. postgresql-libs-8.4.20-8.AXS4.i686.rpm
    MD5: a11b62fb3c404f927ebad72a955fa6ad
    SHA-256: 64714bdd015bdb019fd8cc71bc0759962bc1aa4b8228f62e20ec677055ad98cc
    Size: 205.14 kB