]> rtime.felk.cvut.cz Git - coffee/buildroot.git/commit
postgresql: security bump to version 9.6.5
authorAdam Duskett <aduskett@gmail.com>
Tue, 5 Sep 2017 12:20:10 +0000 (08:20 -0400)
committerPeter Korsgaard <peter@korsgaard.com>
Wed, 6 Sep 2017 12:48:01 +0000 (14:48 +0200)
commit0e3334e25b9b1ef853a83c3ab67822a88ee97842
treeadcb1db669758c68fcd302cc730fd0ec22846eef
parentf16d9637896b79fdfb2a86856d45e60c9d7b9d1d
postgresql: security bump to version 9.6.5

Fixes the following security issues (9.6.4):

CVE-2017-7546: Empty password accepted in some authentication methods
CVE-2017-7547: The "pg_user_mappings" catalog view discloses passwords to users lacking server privileges
CVE-2017-7548: lo_put() function ignores ACLs

For more info, see https://www.postgresql.org/about/news/1772/

[Peter: extend commit message with security fixes info]
Signed-off-by: Adam Duskett <aduskett@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
(cherry picked from commit 95e284bd2732390eb34cb72c798032fd7ac8920c)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/postgresql/postgresql.hash
package/postgresql/postgresql.mk