Your message dated Sat, 22 Jun 2019 08:24:23 +0200
with message-id <[email protected]>
and subject line Re: Bug#930799: unblock: postgresql-11/11.4-1
has caused the Debian Bug report #930799,
regarding unblock: postgresql-11/11.4-1
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
930799: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=930799
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: release.debian.org
Severity: normal
User: [email protected]
Usertags: unblock
Please unblock package postgresql-11. The new version fixes
CVE-2019-10164.
debian/* diff:
diff --git a/debian/changelog b/debian/changelog
index d9bedcb..2f7e899 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,23 @@
+postgresql-11 (11.4-1) unstable; urgency=medium
+
+ * New upstream version.
+ + Fix buffer-overflow hazards in SCRAM verifier parsing
+ (Jonathan Katz, Heikki Linnakangas, Michael Paquier)
+
+ Any authenticated user could cause a stack-based buffer overflow by
+ changing their own password to a purpose-crafted value. In addition to
+ the ability to crash the PostgreSQL server, this could suffice for
+ executing arbitrary code as the PostgreSQL operating system account.
+
+ A similar overflow hazard existed in libpq, which could allow a rogue
+ server to crash a client or perhaps execute arbitrary code as the
+ client's operating system account.
+
+ The PostgreSQL Project thanks Alexander Lakhin for reporting this
+ problem. (CVE-2019-10164)
+
+ -- Christoph Berg <[email protected]> Tue, 18 Jun 2019 11:03:14 +0200
+
postgresql-11 (11.3-1) unstable; urgency=medium
* New upstream version.
unblock postgresql-11/11.4-1
Christoph
--- End Message ---
--- Begin Message ---
Hi Christoph,
On 20-06-2019 22:00, Christoph Berg wrote:
> unblock postgresql-11/11.4-1
Unblocked, thanks.
Paul
signature.asc
Description: OpenPGP digital signature
--- End Message ---