rh-postgresql95-postgresql-9.5.4-1.el7
エラータID: AXSA:2016-654:01
リリース日:
2016/09/08 Thursday - 15:29
題名:
rh-postgresql95-postgresql-9.5.4-1.el7
影響のあるチャネル:
Asianux Server 7 for x86_64
Severity:
Moderate
Description:
[修正内容]
以下項目について対処しました。
[Security Fix]
- 現時点では CVE-2016-5423, CVE-2016-5424 の情報が公開されておりません。
CVE の情報が公開され次第情報をアップデートいたします。
一部CVEの翻訳文はJVNからの引用になります。
http://jvndb.jvn.jp/
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2016-5423
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL pointer dereference and server crash), obtain sensitive memory information, or possibly execute arbitrary code via (1) a CASE expression within the test value subexpression of another CASE or (2) inlining of an SQL function that implements the equality operator used for a CASE expression involving values of different types.
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL pointer dereference and server crash), obtain sensitive memory information, or possibly execute arbitrary code via (1) a CASE expression within the test value subexpression of another CASE or (2) inlining of an SQL function that implements the equality operator used for a CASE expression involving values of different types.
CVE-2016-5424
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a (1) " (double quote), (2) \ (backslash), (3) carriage return, or (4) newline character in a (a) database or (b) role name that is mishandled during an administrative operation.
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a (1) " (double quote), (2) \ (backslash), (3) carriage return, or (4) newline character in a (a) database or (b) role name that is mishandled during an administrative operation.
追加情報:
N/A
ダウンロード:
SRPMS
- rh-postgresql95-postgresql-9.5.4-1.el7.src.rpm
MD5: aa25583ff71b6b7612ac085736adc210
SHA-256: 5356fb2c3c56fef1f849f7eeadb69457fd8395dc08c9e2b459babf39f60bf993
Size: 25.40 MB
Asianux Server 7 for x86_64
- rh-postgresql95-postgresql-9.5.4-1.el7.x86_64.rpm
MD5: bf3b48dae5af548acff2e4433d66318a
SHA-256: c5d04a142706a0a0f60e8c4bb89ef96b7b119244d8178df37821091ca870ae9d
Size: 3.27 MB - rh-postgresql95-postgresql-contrib-9.5.4-1.el7.x86_64.rpm
MD5: ba0f214c9409e1b9566bef6f7525d1fe
SHA-256: 6f82e6f37afabc15efce09913c2dd5e515e8ac97bde3d213d83618158ad216f7
Size: 633.81 kB - rh-postgresql95-postgresql-devel-9.5.4-1.el7.x86_64.rpm
MD5: ab43360c21a54536aab1fbd5c723597a
SHA-256: a9c47030bdd491c7c8cf9bf94634d791545a69371d87ead046efe8e3670f19bf
Size: 1.10 MB - rh-postgresql95-postgresql-docs-9.5.4-1.el7.x86_64.rpm
MD5: 1a0533472e47848325172e57fb974167
SHA-256: 684d7177ba76a62a9d5c7d5d98bb3d1141410d59ceda4dd8d507d9e6b21d8b22
Size: 10.02 MB - rh-postgresql95-postgresql-libs-9.5.4-1.el7.x86_64.rpm
MD5: aded12c1864d36ae64248c1872bb1695
SHA-256: d204e0de4d1ba7a849ec2d732739bc058b8b514723c189f563d3b7f0fe4b7c27
Size: 243.98 kB - rh-postgresql95-postgresql-plperl-9.5.4-1.el7.x86_64.rpm
MD5: c8c597622fc4fca43132cf4bf7f41636
SHA-256: 51e04fbba436127516ebde895efcf4fe9657315ae2b1a12514746747939888b6
Size: 89.15 kB - rh-postgresql95-postgresql-plpython-9.5.4-1.el7.x86_64.rpm
MD5: 4b07dc80b75cc46895f64677b74d96da
SHA-256: c2a1a58e41e38aab8a50ab7099cc967f1162e8e49ef84de900dcba8869803ab2
Size: 98.46 kB - rh-postgresql95-postgresql-pltcl-9.5.4-1.el7.x86_64.rpm
MD5: 98c4a36525ca7da113da11729952a633
SHA-256: 35976d07d126f614fc47d033d40fcc1c4db940b065b5966d9cb48f2958a7243f
Size: 63.11 kB - rh-postgresql95-postgresql-server-9.5.4-1.el7.x86_64.rpm
MD5: 0cbcb2f9246f1ad383e18efdf08c26ca
SHA-256: 8caae2aa97f62079b48710673cbb7ec9880bed17e0fc7aa1d6122e2e458c8d39
Size: 4.32 MB - rh-postgresql95-postgresql-static-9.5.4-1.el7.x86_64.rpm
MD5: aa7dd8ecb3f037b12ccdeea363f1d32d
SHA-256: 818cfe697cfcc9b148e365ceed98f1220e977b21a69d98787cb19671f37a89bc
Size: 129.98 kB - rh-postgresql95-postgresql-test-9.5.4-1.el7.x86_64.rpm
MD5: 41b4608b7ed20ea215a3248c434f7a94
SHA-256: 381efd061b68fffbd4c07aedce938c0be81082040ef86baf6bbf2466f831b6ab
Size: 1.44 MB