[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250039

 
 

909

 
 

195882

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2011:1378 -- centos 5 x86_64 postgresql84

ID: oval:org.secpod.oval:def:201689Date: (C)2012-01-31   (M)2024-04-29
Class: PATCHFamily: unix




PostgreSQL is an advanced object-relational database management system . A signedness issue was found in the way the crypt function in the PostgreSQL pgcrypto module handled 8-bit characters in passwords when using Blowfish hashing. Up to three characters immediately preceding a non-ASCII character had no effect on the hash result, thus shortening the effective password length. This made brute-force guessing more efficient as several different passwords were hashed to the same value. Note: Due to the CVE-2011-2483 fix, after installing this update some users may not be able to log in to applications that store user passwords, hashed with Blowfish using the PostgreSQL crypt function, in a back-end PostgreSQL database. Unsafe processing can be re-enabled for specific passwords by changing their hash prefix to "$2x$". These updated postgresql84 packages upgrade PostgreSQL to version 8.4.9. If the postgresql service is running, it will be automatically restarted after installing this update.

Platform:
CentOS 5
Product:
postgresql84
Reference:
CESA-2011:1378
CVE-2011-2483
CVE    1
CVE-2011-2483
CPE    2
cpe:/a:postgresql:postgresql84
cpe:/o:centos:centos:5

© SecPod Technologies