Fedora 7 : postgresql-8.2.6-1.fc7 (2008-0552)

High Nessus Plugin ID 29948


The remote Fedora host is missing a security update.


- Mon Jan 7 2008 Tom Lane <tgl at redhat.com> 8.2.6-1

- Update to PostgreSQL 8.2.6 to fix CVE-2007-4769, CVE-2007-4772, CVE-2007-6067, CVE-2007-6600, CVE-2007-6601

- Make initscript and pam config files be installed unconditionally; seems new buildroots don't necessarily have those directories in place

- Thu Sep 20 2007 Tom Lane <tgl at redhat.com> 8.2.5-1

- Update to PostgreSQL 8.2.5 and pgtcl 1.6.0

- Fix multilib problem for /usr/include/ecpg_config.h (which is new in 8.2.x)

- Use tzdata package's data files instead of private copy, so that postgresql-server need not be turned for routine timezone updates

- Don't remove postgres user/group during RPM uninstall, per Fedora packaging guidelines

- Recent perl changes in rawhide mean we need a more specific BuildRequires

- Wed Jun 20 2007 Tom Lane <tgl at redhat.com> 8.2.4-2

- Fix oversight in postgresql-test makefile: pg_regress isn't a shell script anymore. Per upstream bug 3398.

- Tue Apr 24 2007 Tom Lane <tgl at redhat.com> 8.2.4-1

- Update to PostgreSQL 8.2.4 for CVE-2007-2138, data loss bugs Resolves: #237682

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.


Update the affected packages.

See Also








Plugin Details

Severity: High

ID: 29948

File Name: fedora_2008-0552.nasl

Version: $Revision: 1.15 $

Type: local

Agent: unix

Published: 2008/01/14

Modified: 2016/12/08

Dependencies: 12634

Risk Information

Risk Factor: High


Base Score: 7.2

Temporal Score: 6.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:postgresql, p-cpe:/a:fedoraproject:fedora:postgresql-contrib, p-cpe:/a:fedoraproject:fedora:postgresql-debuginfo, p-cpe:/a:fedoraproject:fedora:postgresql-devel, p-cpe:/a:fedoraproject:fedora:postgresql-docs, p-cpe:/a:fedoraproject:fedora:postgresql-libs, p-cpe:/a:fedoraproject:fedora:postgresql-plperl, p-cpe:/a:fedoraproject:fedora:postgresql-plpython, p-cpe:/a:fedoraproject:fedora:postgresql-pltcl, p-cpe:/a:fedoraproject:fedora:postgresql-python, p-cpe:/a:fedoraproject:fedora:postgresql-server, p-cpe:/a:fedoraproject:fedora:postgresql-tcl, p-cpe:/a:fedoraproject:fedora:postgresql-test, cpe:/o:fedoraproject:fedora:7

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2008/01/11

Reference Information

CVE: CVE-2007-4769, CVE-2007-4772, CVE-2007-6067, CVE-2007-6600, CVE-2007-6601

BID: 27163

FEDORA: 2008-0552

CWE: 189, 264, 287, 399