rh-postgresql94-postgresql-9.4.14-2.AXS4

エラータID: AXSA:2017-2465:03

リリース日: 
2017/12/11 Monday - 12:12
題名: 
rh-postgresql94-postgresql-9.4.14-2.AXS4
影響のあるチャネル: 
Asianux Server 4 for x86_64
Severity: 
Moderate
Description: 

PostgreSQL is an advanced object-relational database management system (DBMS).

Security Fix(es):

* Privilege escalation flaws were found in the initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine. (CVE-2017-12172, CVE-2017-15097)

Note: This patch drops the script privileges from root to the postgres user. Therefore, we dropped the --new-systemd-unit option for security reasons. Please use the root-only script postgresql-new-systemd-unit.

Asianux would like to thank the PostgreSQL project for reporting CVE-2017-12172. The CVE-2017-15097 issue was discovered by Pedro Barbosa (Asianux) and the PostgreSQL project. Upstream acknowledges Antoine Scemama (Brainloop) as the original reporter of these issues.

CVE-2017-12172
PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10,
9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runs
under a non-root operating system account, and database superusers
have effective ability to run arbitrary code under that system
account. PostgreSQL provides a script for starting the database server
during system boot. Packages of PostgreSQL for many operating systems
provide their own, packager-authored startup implementations. Several
implementations use a log file name that the database superuser can
replace with a symbolic link. As root, they open(), chmod() and/or
chown() this log file name. This often suffices for the database
superuser to escalate to root privileges when root starts the server.
CVE-2017-15097
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be
provided.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. rh-postgresql94-postgresql-9.4.14-2.AXS4.src.rpm
    MD5: 1e4b6376f022f0316ac46b29d0c566c0
    SHA-256: 9a71e5a0b9ff9fdc9c59f442eb82b7cd81c1ca3182615a062db022e4f7aea30b
    Size: 24.47 MB

Asianux Server 4 for x86_64
  1. rh-postgresql94-postgresql-9.4.14-2.AXS4.x86_64.rpm
    MD5: 447a46077ed65722a68d0dd5454bbd27
    SHA-256: 95f5e01666080a61edd1ee8b03a7284aa7e44c4f0f3e6ae8ef3ef54ef232b34a
    Size: 3.20 MB
  2. rh-postgresql94-postgresql-contrib-9.4.14-2.AXS4.x86_64.rpm
    MD5: 06e6e2017626e3f5aecd72d7579acb28
    SHA-256: 007ea8a74029cf61433b94c43d780e68642d90d3ae8c80a04c99539d3b61ab1d
    Size: 524.02 kB
  3. rh-postgresql94-postgresql-devel-9.4.14-2.AXS4.x86_64.rpm
    MD5: 6c7ef28b1d73d6297869fedd2a55870f
    SHA-256: 000b70638ad64ece141e2e686ca108d45097cc43d8ec70d7d3c0c6fd6df9c19f
    Size: 1.01 MB
  4. rh-postgresql94-postgresql-docs-9.4.14-2.AXS4.x86_64.rpm
    MD5: 454c567c3ade3aef8ad8924ec0c50566
    SHA-256: 706ac3ff2b1b206e6d3e38a972691e1d9f487a808e0e89b05c6db34ba5e73f44
    Size: 9.90 MB
  5. rh-postgresql94-postgresql-libs-9.4.14-2.AXS4.x86_64.rpm
    MD5: 4f3f40ed14bc24186274a3ae8cf83dfe
    SHA-256: 507c7567fd0e46a05652a421f126846c18a1649eceb6a824f6c77f24e5ac525b
    Size: 225.36 kB
  6. rh-postgresql94-postgresql-plperl-9.4.14-2.AXS4.x86_64.rpm
    MD5: 60a21712d47f3f2ed51679ea080dd5fe
    SHA-256: 52208bbd725620355d011367059baedb92553c914c4b8a2741d1482b83b6bc58
    Size: 81.24 kB
  7. rh-postgresql94-postgresql-plpython-9.4.14-2.AXS4.x86_64.rpm
    MD5: dbb0b263d285024648dd194f54ce1d10
    SHA-256: e224185efcf60e524931d520833058051a1f8e964f6f8e5c9d4ff15e2caefcc6
    Size: 93.93 kB
  8. rh-postgresql94-postgresql-pltcl-9.4.14-2.AXS4.x86_64.rpm
    MD5: 81c14b8b6eae7c28e627e70881c5336b
    SHA-256: ac9571e63cab4f557ed304f99b54d6359d8ba6d15461db041644cafd4c52cb98
    Size: 58.96 kB
  9. rh-postgresql94-postgresql-server-9.4.14-2.AXS4.x86_64.rpm
    MD5: 166d332b8a8c0b34b22b280bbcc748ee
    SHA-256: 5cf8de853dcb2cf8ba839a4006bd553d1fa6cf557a05791805ba775b973b8ce9
    Size: 4.60 MB
  10. rh-postgresql94-postgresql-test-9.4.14-2.AXS4.x86_64.rpm
    MD5: 27bc405f04c9895c159c8229a3a0742d
    SHA-256: e62e5a381f26713abfa95a40d1bcd054811d9914c8b1a2b0a855114c95b29b11
    Size: 2.18 MB
  11. rh-postgresql94-postgresql-upgrade-9.4.14-2.AXS4.x86_64.rpm
    MD5: e4a601b6ed192654944faf6e0af8d992
    SHA-256: ab3cc9513193b8011ad438c6eb336feac607b66c9b1e720a17b244e5c7a6755c
    Size: 80.14 kB