[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] CVE-2018-1057: postgresql-10, postgresql-9.6, postgresql-9.4, postgresql-9.1
Christoph Berg
myon at debian.org
Tue Feb 27 15:21:46 UTC 2018
Christoph Berg pushed to branch master at Debian Security Tracker / security-tracker
Commits:
407bd6a3 by Christoph Berg at 2018-02-27T16:21:01+01:00
CVE-2018-1057: postgresql-10, postgresql-9.6, postgresql-9.4, postgresql-9.1
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -17274,8 +17274,17 @@ CVE-2018-1059
RESERVED
CVE-2018-1058
RESERVED
-CVE-2018-1057
- RESERVED
+CVE-2018-1057 (Security implications of using the default search_path and public schema)
+ - postgresql-10 10.3-1
+ - postgresql-9.6 <removed>
+ [stretch] - postgresql-9.6.8-0+deb9u1
+ - postgresql-9.4 <removed>
+ [jessie] - postgresql-9.4.17-0+deb8u1
+ - postgresql-9.1 <removed>
+ [jessie] - postgresql-9.1 <not-affected> (postgresql-9.1 in jessie is PL/Perl only)
+ NOTE: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=3d2aed664ee8271fd6c721ed0aa10168cda112ea
+ NOTE: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=582edc369cdbd348d68441fc50fa26a84afd0c1a
+ NOTE: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=5770172cb0c9df9e6ce27c507b449557e5b45124
CVE-2018-1056 [heap buffer overflow while running advzip]
RESERVED
{DLA-1281-1}
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/407bd6a3577c4a21dac22dacac8d8ed6c33a604a
---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/407bd6a3577c4a21dac22dacac8d8ed6c33a604a
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-commits/attachments/20180227/710d975a/attachment.html>
More information about the Secure-testing-commits
mailing list