[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] CVE-2018-1057: postgresql-10, postgresql-9.6, postgresql-9.4, postgresql-9.1

Christoph Berg myon at debian.org
Tue Feb 27 15:21:46 UTC 2018


Christoph Berg pushed to branch master at Debian Security Tracker / security-tracker


Commits:
407bd6a3 by Christoph Berg at 2018-02-27T16:21:01+01:00
CVE-2018-1057: postgresql-10, postgresql-9.6, postgresql-9.4, postgresql-9.1

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -17274,8 +17274,17 @@ CVE-2018-1059
 	RESERVED
 CVE-2018-1058
 	RESERVED
-CVE-2018-1057
-	RESERVED
+CVE-2018-1057 (Security implications of using the default search_path and public schema)
+	- postgresql-10 10.3-1
+	- postgresql-9.6 <removed>
+	[stretch] - postgresql-9.6.8-0+deb9u1
+	- postgresql-9.4 <removed>
+	[jessie] - postgresql-9.4.17-0+deb8u1
+	- postgresql-9.1 <removed>
+	[jessie] - postgresql-9.1 <not-affected> (postgresql-9.1 in jessie is PL/Perl only)
+	NOTE: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=3d2aed664ee8271fd6c721ed0aa10168cda112ea
+	NOTE: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=582edc369cdbd348d68441fc50fa26a84afd0c1a
+	NOTE: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=5770172cb0c9df9e6ce27c507b449557e5b45124
 CVE-2018-1056 [heap buffer overflow while running advzip]
 	RESERVED
 	{DLA-1281-1}



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/407bd6a3577c4a21dac22dacac8d8ed6c33a604a

---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/407bd6a3577c4a21dac22dacac8d8ed6c33a604a
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-commits/attachments/20180227/710d975a/attachment.html>


More information about the Secure-testing-commits mailing list