New upstream microreleases 9.1.15, 9.3.6, 9.4.1
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| postgresql-8.4 (Ubuntu) |
Undecided
|
Unassigned | |||
| Lucid |
Undecided
|
Marc Deslauriers | |||
| postgresql-9.1 (Ubuntu) |
Undecided
|
Unassigned | |||
| Precise |
Undecided
|
Marc Deslauriers | |||
| Trusty |
Undecided
|
Unassigned | |||
| postgresql-9.3 (Ubuntu) |
Undecided
|
Unassigned | |||
| Trusty |
Undecided
|
Marc Deslauriers | |||
| postgresql-9.4 (Ubuntu) |
Undecided
|
Unassigned | |||
| Utopic |
Undecided
|
Marc Deslauriers | |||
| Vivid |
Undecided
|
Unassigned | |||
Bug Description
PostgreSQL has released new versions yesterday: http://
These fix a bunch of security issues, as well as the usual set of bug fixes.
| Martin Pitt (pitti) wrote : | #1 |
| no longer affects: | postgresql-8.4 (Ubuntu Precise) |
| no longer affects: | postgresql-8.4 (Ubuntu Trusty) |
| no longer affects: | postgresql-8.4 (Ubuntu Utopic) |
| no longer affects: | postgresql-9.1 (Ubuntu Lucid) |
| no longer affects: | postgresql-9.4 (Ubuntu Trusty) |
| no longer affects: | postgresql-9.4 (Ubuntu Precise) |
| no longer affects: | postgresql-9.4 (Ubuntu Lucid) |
| no longer affects: | postgresql-8.4 (Ubuntu Vivid) |
| Changed in postgresql-8.4 (Ubuntu): | |
| status: | New → Invalid |
| no longer affects: | postgresql-9.1 (Ubuntu Vivid) |
| no longer affects: | postgresql-9.1 (Ubuntu Utopic) |
| Changed in postgresql-9.1 (Ubuntu): | |
| status: | New → Invalid |
| no longer affects: | postgresql-9.3 (Ubuntu Lucid) |
| no longer affects: | postgresql-9.3 (Ubuntu Vivid) |
| no longer affects: | postgresql-9.3 (Ubuntu Precise) |
| no longer affects: | postgresql-9.3 (Ubuntu Utopic) |
| Changed in postgresql-9.3 (Ubuntu): | |
| status: | New → Invalid |
| Changed in postgresql-9.4 (Ubuntu Vivid): | |
| status: | New → Fix Committed |
| Changed in postgresql-9.4 (Ubuntu Utopic): | |
| assignee: | nobody → Martin Pitt (pitti) |
| status: | New → In Progress |
| Changed in postgresql-9.3 (Ubuntu Trusty): | |
| status: | New → In Progress |
| Changed in postgresql-9.1 (Ubuntu Trusty): | |
| status: | New → In Progress |
| Changed in postgresql-9.1 (Ubuntu Precise): | |
| status: | New → In Progress |
| Martin Pitt (pitti) wrote : | #2 |
8.4 for lucid requires some backporting, as it isn't supported upstream any more.
CVE-2015-0241:
http://
http://
CVE-2015-0242:
http://
but this does not affect Ubuntu as it uses the glibc snprintf() there instead of its own (which is mostly for Windows).
CVE-2015-0243:
http://
http://
CVE-2015-0244:
http://
CVE-2014-8161:
http://
| Changed in postgresql-8.4 (Ubuntu Lucid): | |
| assignee: | nobody → Martin Pitt (pitti) |
| status: | New → In Progress |
| Changed in postgresql-9.4 (Ubuntu Utopic): | |
| assignee: | Martin Pitt (pitti) → nobody |
| Martin Pitt (pitti) wrote : | #3 |
Packages for precise to utopic are ready and tested: http://
I'm still backporting for lucid, though.
| information type: | Public → Public Security |
| Martin Pitt (pitti) wrote : | #4 |
The fix for the column privilege leaks in error messages (http://
| Martin Pitt (pitti) wrote : | #5 |
lucid is now ready and tested as well.
| Changed in postgresql-8.4 (Ubuntu Lucid): | |
| assignee: | Martin Pitt (pitti) → Ubuntu Security Team (ubuntu-security) |
| Changed in postgresql-8.4 (Ubuntu Lucid): | |
| assignee: | Ubuntu Security Team (ubuntu-security) → Marc Deslauriers (mdeslaur) |
| Changed in postgresql-9.1 (Ubuntu Precise): | |
| assignee: | nobody → Marc Deslauriers (mdeslaur) |
| Changed in postgresql-9.3 (Ubuntu Trusty): | |
| assignee: | nobody → Marc Deslauriers (mdeslaur) |
| Changed in postgresql-9.4 (Ubuntu Utopic): | |
| assignee: | nobody → Marc Deslauriers (mdeslaur) |
| Launchpad Janitor (janitor) wrote : | #6 |
This bug was fixed in the package postgresql-9.1 - 9.1.15-
---------------
postgresql-9.1 (9.1.15-
* New upstream bug fix release (LP: #1418928). No effective changes for
PL/Perl, the version must just be higher than the one in precise, to not
break upgrades.
-- Martin Pitt <email address hidden> Fri, 06 Feb 2015 12:53:38 +0100
| Changed in postgresql-9.1 (Ubuntu Trusty): | |
| status: | In Progress → Fix Released |
| Launchpad Janitor (janitor) wrote : | #7 |
This bug was fixed in the package postgresql-9.3 - 9.3.6-0ubuntu0.
---------------
postgresql-9.3 (9.3.6-
* New upstream security/bug fix release (LP: #1418928)
- Fix buffer overruns in to_char() [CVE-2015-0241]
- Fix buffer overruns in contrib/pgcrypto [CVE-2015-0243]
- Fix possible loss of frontend/backend protocol synchronization after an
error [CVE-2015-0244]
- Fix information leak via constraint-
[
- See release notes for details about other fixes:
http://
-- Martin Pitt <email address hidden> Fri, 06 Feb 2015 12:47:00 +0100
| Changed in postgresql-9.3 (Ubuntu Trusty): | |
| status: | In Progress → Fix Released |
| Launchpad Janitor (janitor) wrote : | #8 |
This bug was fixed in the package postgresql-9.4 - 9.4.1-0ubuntu0.
---------------
postgresql-9.4 (9.4.1-
* New upstream security/bug fix release (LP: #1418928)
- Fix buffer overruns in to_char() [CVE-2015-0241]
- Fix buffer overruns in contrib/pgcrypto [CVE-2015-0243]
- Fix possible loss of frontend/backend protocol synchronization after an
error [CVE-2015-0244]
- Fix information leak via constraint-
[
- See release notes for details about other fixes:
http://
-- Martin Pitt <email address hidden> Fri, 06 Feb 2015 12:31:46 +0100
| Changed in postgresql-9.4 (Ubuntu Utopic): | |
| status: | In Progress → Fix Released |
| Launchpad Janitor (janitor) wrote : | #9 |
This bug was fixed in the package postgresql-9.1 - 9.1.15-
---------------
postgresql-9.1 (9.1.15-
* New upstream security/bug fix release (LP: #1418928)
- Fix buffer overruns in to_char() [CVE-2015-0241]
- Fix buffer overruns in contrib/pgcrypto [CVE-2015-0243]
- Fix possible loss of frontend/backend protocol synchronization after an
error [CVE-2015-0244]
- Fix information leak via constraint-
[
- See release notes for details about other fixes:
http://
-- Martin Pitt <email address hidden> Fri, 06 Feb 2015 12:58:26 +0100
| Changed in postgresql-9.1 (Ubuntu Precise): | |
| status: | In Progress → Fix Released |
| Changed in postgresql-8.4 (Ubuntu Lucid): | |
| status: | In Progress → Fix Released |
| Changed in postgresql-9.4 (Ubuntu Vivid): | |
| status: | Fix Committed → Fix Released |
| Martin Pitt (pitti) wrote : | #10 |
Sorry, I forgot to take out the changelog message for CVE-2014-8161 from the -8.4/lucid update (see comment 4). This is misleading, there is no such patch and this vulnerability is *not* fixed in lucid.


https:/ /launchpad. net/ubuntu/ +source/ postgresql- 9.4/9.4. 1-1 is in vivid-proposed, but currently stuck on some reverse test dependency failures.