-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3270-1 security@debian.org http://www.debian.org/security/ Christoph Berg May 22, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : postgresql-9.4 CVE ID : CVE-2015-3165 CVE-2015-3166 CVE-2015-3167 Several vulnerabilities have been found in PostgreSQL-9.4, a SQL database system. CVE-2015-3165 (Remote crash) SSL clients disconnecting just before the authentication timeout expires can cause the server to crash. CVE-2015-3166 (Information exposure) The replacement implementation of snprintf() failed to check for errors reported by the underlying system library calls; the main case that might be missed is out-of-memory situations. In the worst case this might lead to information exposure. CVE-2015-3167 (Possible side-channel key exposure) In contrib/pgcrypto, some cases of decryption with an incorrect key could report other error message texts. Fix by using a one-size-fits-all message. For the stable distribution (jessie), these problems have been fixed in version 9.4.2-0+deb8u1. For the testing distribution (stretch), these problems will be fixed soon. For the unstable distribution (sid), these problems have been fixed in version 9.4.2-1. We recommend that you upgrade your postgresql-9.4 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJVX0iTAAoJEAVMuPMTQ89EOo4P/08xy75M/fh+SGhqc2BHHlYz rw2R0p52t6ijS+zt6Z9klLvcFE+tuJNB/cr8CnW1PNuOcejwsUkyHahmxXROG4Y4 wg89EJ/e2kVtZxNGiTMDpspwmOKLqZSf4UI3E/xCmxU6tiHJL/Ihn/MJUr3WwEZS yiUs6fZUpuxo9X8Hoi419fpby5Saefx5pYgQ+i3Za4cD90pWi8t/zPUfwpfaIPMS s1z0165j7pKdevLUCVhKLsZF2CEcykrVdXASEscbGWoqeH2+Hf9l7A0rW1QRL1eE CJyFOg3O/Git4JmnmV5A/uI5YVEUALzJYweuSilZg3gRz6sLV9/CI5IRirZlyGSA JYiFjJZMtCjmjPaMoBnCH5RhPh7jkDO2KJ/8UkvH9M/8AMwy1ex4aixGCjPvJeUL PM4sShtUe9jJszfkJliX1KtyXyvyUbCQl2gATFQUJlOnn5HvWE7J5R3mxKR+k12P SyF+C6Exzd90UjYPNwaFkIf54Pgmwd90wutO3wf63zyQxPVMGyTuMVHW0Kc5phI7 GGxgQjMFKOi7QMDBhVoIcdyEJndqKZOwpmTUi7NlbDGPx0RiExKIzC5DSnz0VYoX uRdRPF/jQqdbnVnHAv79BJT9QtyjUNVNXIccSdZiG33bLSiSZNxw4btY/npuDCTN 7zkVlxdUQcdTogIM2OAG =CFYg -----END PGP SIGNATURE-----