Oval Definition:oval:com.redhat.rhsa:def:20172860
Revision Date:2017-10-05Version:635
Title:RHSA-2017:2860: postgresql security update (Moderate)
Description:PostgreSQL is an advanced object-relational database management system (DBMS).

Security Fix(es):

  • It was found that authenticating to a PostgreSQL database account with an empty password was possible despite libpq's refusal to send an empty password. A remote attacker could potentially use this flaw to gain access to database accounts with empty passwords. (CVE-2017-7546)

    Red Hat would like to thank the PostgreSQL project for reporting this issue. Upstream acknowledges Ben de Graaff, Jelte Fennema, and Jeroen van der Ham as the original reporters.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2017-7546
    RHSA-2017:2860
    RHSA-2017:2860-00
    RHSA-2017:2860-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • postgresql is earlier than 0:8.4.20-8.el6_9
  • AND postgresql is signed with Red Hat redhatrelease2 key
  • postgresql-contrib is earlier than 0:8.4.20-8.el6_9
  • AND postgresql-contrib is signed with Red Hat redhatrelease2 key
  • postgresql-devel is earlier than 0:8.4.20-8.el6_9
  • AND postgresql-devel is signed with Red Hat redhatrelease2 key
  • postgresql-docs is earlier than 0:8.4.20-8.el6_9
  • AND postgresql-docs is signed with Red Hat redhatrelease2 key
  • postgresql-libs is earlier than 0:8.4.20-8.el6_9
  • AND postgresql-libs is signed with Red Hat redhatrelease2 key
  • postgresql-plperl is earlier than 0:8.4.20-8.el6_9
  • AND postgresql-plperl is signed with Red Hat redhatrelease2 key
  • postgresql-plpython is earlier than 0:8.4.20-8.el6_9
  • AND postgresql-plpython is signed with Red Hat redhatrelease2 key
  • postgresql-pltcl is earlier than 0:8.4.20-8.el6_9
  • AND postgresql-pltcl is signed with Red Hat redhatrelease2 key
  • postgresql-server is earlier than 0:8.4.20-8.el6_9
  • AND postgresql-server is signed with Red Hat redhatrelease2 key
  • postgresql-test is earlier than 0:8.4.20-8.el6_9
  • AND postgresql-test is signed with Red Hat redhatrelease2 key
  • BACK