Accepted postgresql 7.4.7-6sarge6 (source i386 all)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sun, 13 Jan 2008 14:56:44 +0100
Source: postgresql
Binary: postgresql-client libecpg4 libpgtcl-dev libpq3 postgresql-doc libecpg-dev postgresql-dev postgresql libpgtcl postgresql-contrib
Architecture: source i386 all
Version: 7.4.7-6sarge6
Distribution: oldstable-security
Urgency: low
Maintainer: Martin Pitt <mpitt@debian.org>
Changed-By: Martin Pitt <mpitt@debian.org>
Description:
libecpg-dev - development files for ECPG (Embedded PostgreSQL for C)
libecpg4 - run-time library for ECPG programs
libpgtcl - Tcl procedural language, library and front-end for PostgreSQL
libpgtcl-dev - Tcl library for PostgreSQL - development files
libpq3 - PostgreSQL C client library
postgresql - object-relational SQL database management system
postgresql-client - front-end programs for PostgreSQL
postgresql-contrib - additional facilities for PostgreSQL
postgresql-dev - development files for libpq (PostgreSQL library)
postgresql-doc - documentation for the PostgreSQL database management system
Changes:
postgresql (7.4.7-6sarge6) oldstable-security; urgency=low
.
* SECURITY UPDATE: User privilege escalation.
* Add debian/patches/63dblink_restrictions.patch:
- Require non-superusers who use "/contrib/dblink" to use only password
authentication, to prevent abusing the postmaster as source for remote
attacks with trust or ident authentication.
[CVE-2007-3278, CVE-2007-6601]
- Patch backported from 7.4.19 CVS:
http://developer.postgresql.org/cvsweb.cgi/pgsql/contrib/dblink/dblink.c.diff?r1=1.25.4.4;r2=1.25.4.6
http://developer.postgresql.org/cvsweb.cgi/pgsql/contrib/dblink/dblink.sql.in.diff?r1=1.8;r2=1.8.4.1
Files:
5111d74c719c877925a5d85609cc3dfd 985 misc optional postgresql_7.4.7-6sarge6.dsc
4cf8d83170ab5dcf6b0a36790ff0de9f 198884 misc optional postgresql_7.4.7-6sarge6.diff.gz
0dbaddc80dedb89399383f50b3185f90 2397446 doc optional postgresql-doc_7.4.7-6sarge6_all.deb
a61c60740a6d17ea3559ce5e7afbbdca 3801078 misc optional postgresql_7.4.7-6sarge6_i386.deb
7fe4064b57a43221103e51f05af1b241 541118 misc optional postgresql-client_7.4.7-6sarge6_i386.deb
c02b7cc603534f7b0f86433c66d09918 517364 libdevel optional postgresql-dev_7.4.7-6sarge6_i386.deb
bf6b4fd7745c2baad3f2cd740905c337 129494 libs optional libpq3_7.4.7-6sarge6_i386.deb
751eeba33bdd9443a2e1b78f106bb76f 97454 libs optional libecpg4_7.4.7-6sarge6_i386.deb
020165bfb6274dbbd1ea9c379831de0e 209068 libdevel optional libecpg-dev_7.4.7-6sarge6_i386.deb
b85a163131bbf527aad45eafc1629196 79452 libs optional libpgtcl_7.4.7-6sarge6_i386.deb
abd1d8cf001392e81ac908528bdd2c51 57122 libdevel optional libpgtcl-dev_7.4.7-6sarge6_i386.deb
c1b8e6c7265ad11746d802d67e312f58 628026 misc optional postgresql-contrib_7.4.7-6sarge6_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFHiiqIDecnbV4Fd/IRAr2tAKCoDEJieKiQt9eG9nGG0Ulwp/pXYACg9Mtr
+KhF+kyJ68l00aztOzMDSE8=
=wUS8
-----END PGP SIGNATURE-----
Accepted:
libecpg-dev_7.4.7-6sarge6_i386.deb
to pool/main/p/postgresql/libecpg-dev_7.4.7-6sarge6_i386.deb
libecpg4_7.4.7-6sarge6_i386.deb
to pool/main/p/postgresql/libecpg4_7.4.7-6sarge6_i386.deb
libpgtcl-dev_7.4.7-6sarge6_i386.deb
to pool/main/p/postgresql/libpgtcl-dev_7.4.7-6sarge6_i386.deb
libpgtcl_7.4.7-6sarge6_i386.deb
to pool/main/p/postgresql/libpgtcl_7.4.7-6sarge6_i386.deb
libpq3_7.4.7-6sarge6_i386.deb
to pool/main/p/postgresql/libpq3_7.4.7-6sarge6_i386.deb
postgresql-client_7.4.7-6sarge6_i386.deb
to pool/main/p/postgresql/postgresql-client_7.4.7-6sarge6_i386.deb
postgresql-contrib_7.4.7-6sarge6_i386.deb
to pool/main/p/postgresql/postgresql-contrib_7.4.7-6sarge6_i386.deb
postgresql-dev_7.4.7-6sarge6_i386.deb
to pool/main/p/postgresql/postgresql-dev_7.4.7-6sarge6_i386.deb
postgresql-doc_7.4.7-6sarge6_all.deb
to pool/main/p/postgresql/postgresql-doc_7.4.7-6sarge6_all.deb
postgresql_7.4.7-6sarge6.diff.gz
to pool/main/p/postgresql/postgresql_7.4.7-6sarge6.diff.gz
postgresql_7.4.7-6sarge6.dsc
to pool/main/p/postgresql/postgresql_7.4.7-6sarge6.dsc
postgresql_7.4.7-6sarge6_i386.deb
to pool/main/p/postgresql/postgresql_7.4.7-6sarge6_i386.deb