[ubuntu/precise-security] postgresql-common 129ubuntu1.2 (Accepted)

Steve Langasek steve.langasek at canonical.com
Mon May 3 13:04:53 UTC 2021


postgresql-common (129ubuntu1.2) precise-security; urgency=medium

  * SECURITY UPDATE: symlink attack vulnerability
    - drop privileges when creating log file in pg_ctlcluster.
    - c8989206ec360f199400c74f129f7b4cb878c1ee
    - CVE-2016-1255
  * SECURITY UPDATE: symlink attack vulnerability in init/helper scripts
    (LP: #1727209)
    - use lchown instead of chown in pg_createcluster, pg_ctlcluster,
      pg_upgradecluster.
    - 8b4d0a889a8287181c4bdf46462db9b737a6e25d
    - CVE-2017-8806

Date: 2017-11-27 17:21:12.246884+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
Signed-By: Steve Langasek <steve.langasek at canonical.com>
https://launchpad.net/ubuntu/+source/postgresql-common/129ubuntu1.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Precise-changes mailing list