SuSE 11.2 Security Update : PostgreSQL (SAT Patch Number 7585)

High Nessus Plugin ID 65829

Synopsis

The remote SuSE 11 host is missing one or more security updates.

Description

This update to version 9.1.9 fixes :

- Fix insecure parsing of server command-line switches.
(CVE-2013-1899)

- Reset OpenSSL randomness state in each postmaster child process. (CVE-2013-1900)

- Make REPLICATION privilege checks test current user not authenticated user. (CVE-2013-1901)

Solution

Apply SAT patch number 7585.

See Also

https://bugzilla.novell.com/show_bug.cgi?id=812525

http://support.novell.com/security/cve/CVE-2013-1899.html

http://support.novell.com/security/cve/CVE-2013-1900.html

http://support.novell.com/security/cve/CVE-2013-1901.html

Plugin Details

Severity: High

ID: 65829

File Name: suse_11_libecpg6-130402.nasl

Version: Revision: 1.7

Type: local

Agent: unix

Published: 2013/04/07

Updated: 2015/01/13

Dependencies: 12634

Risk Information

Risk Factor: High

CVSS v2.0

Base Score: 8.5

Vector: CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:11:libecpg6, p-cpe:/a:novell:suse_linux:11:libpq5, p-cpe:/a:novell:suse_linux:11:libpq5-32bit, p-cpe:/a:novell:suse_linux:11:postgresql91, p-cpe:/a:novell:suse_linux:11:postgresql91-contrib, p-cpe:/a:novell:suse_linux:11:postgresql91-docs, p-cpe:/a:novell:suse_linux:11:postgresql91-server, cpe:/o:novell:suse_linux:11

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 2013/04/02

Reference Information

CVE: CVE-2013-1899, CVE-2013-1900, CVE-2013-1901