postgresql-8.4 (8.4.17-0ubuntu10.04) lucid-security; urgency=low * New upstream security/bug fix release: (LP: #1163184) - Reset OpenSSL randomness state in each postmaster child process. This avoids a scenario wherein random numbers generated by "contrib/pgcrypto" functions might be relatively easy for another database user to guess. The risk is only significant when the postmaster is configured with ssl = on but most connections don't use SSL encryption. [CVE-2013-1900] - Fix GiST indexes to not use "fuzzy" geometric comparisons when it's not appropriate to do so. The core geometric types perform comparisons using "fuzzy" equality, but gist_box_same must do exact comparisons, else GiST indexes using it might become inconsistent. After installing this update, users should "REINDEX" any GiST indexes on box, polygon, circle, or point columns, since all of these use gist_box_same. - Fix erroneous range-union and penalty logic in GiST indexes that use "contrib/btree_gist" for variable-width data types, that is text, bytea, bit, and numeric columns. These errors could result in inconsistent indexes in which some keys that are present would not be found by searches, and also in useless index bloat. Users are advised to "REINDEX" such indexes after installing this update. - Fix bugs in GiST page splitting code for multi-column indexes. These errors could result in inconsistent indexes in which some keys that are present would not be found by searches, and also in indexes that are unnecessarily inefficient to search. Users are advised to "REINDEX" multi-column GiST indexes after installing this update. - See HISTORY/changelog.gz for the other bug fixes. -- Martin Pitt <martin.p...@ubuntu.com> Tue, 02 Apr 2013 12:31:54 +0200
** Changed in: postgresql-8.4 (Ubuntu Precise) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Desktop Packages, which is subscribed to postgresql-9.1 in Ubuntu. https://bugs.launchpad.net/bugs/1163184 Title: New upstream microreleases 9.1.9, 8.4.17 Status in “postgresql-8.3” package in Ubuntu: Fix Released Status in “postgresql-8.4” package in Ubuntu: Invalid Status in “postgresql-9.1” package in Ubuntu: Fix Committed Status in “postgresql-8.4” source package in Lucid: Fix Released Status in “postgresql-9.1” source package in Oneiric: Fix Released Status in “postgresql-8.4” source package in Precise: Fix Released Status in “postgresql-9.1” source package in Precise: Fix Released Status in “postgresql-9.1” source package in Quantal: Fix Released Status in “postgresql-8.3” source package in Raring: Fix Released Status in “postgresql-9.1” source package in Raring: Fix Committed Bug description: PostgreSQL will announce new upstream microreleases in two days which include three security issues for 9.1 and one for 8.4. I'll update the description with the official annoucement once it goes public. One of the 9.1 ones is a remote data corruption vulnerability, so we need to take special care to not prematurely leak this, as well as push out the updates in timely manner. Coordinated release time: Thursday, 2013-04-04 15:00 UTC To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/postgresql-8.3/+bug/1163184/+subscriptions -- Mailing list: https://launchpad.net/~desktop-packages Post to : desktop-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~desktop-packages More help : https://help.launchpad.net/ListHelp