[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2011:1378-01 -- Redhat postgresql84

ID: oval:org.secpod.oval:def:500012Date: (C)2012-01-31   (M)2023-12-07
Class: PATCHFamily: unix




PostgreSQL is an advanced object-relational database management system . A signedness issue was found in the way the crypt function in the PostgreSQL pgcrypto module handled 8-bit characters in passwords when using Blowfish hashing. Up to three characters immediately preceding a non-ASCII character had no effect on the hash result, thus shortening the effective password length. This made brute-force guessing more efficient as several different passwords were hashed to the same value. Note: Due to the CVE-2011-2483 fix, after installing this update some users may not be able to log in to applications that store user passwords, hashed with Blowfish using the PostgreSQL crypt function, in a back-end PostgreSQL database. Unsafe processing can be re-enabled for specific passwords by changing their hash prefix to "$2x$". These updated postgresql84 packages upgrade PostgreSQL to version 8.4.9. If the postgresql service is running, it will be automatically restarted after installing this update.

Platform:
Red Hat Enterprise Linux 5
Product:
postgresql84
Reference:
RHSA-2011:1378-01
CVE-2011-2483
CVE    1
CVE-2011-2483
CPE    2
cpe:/o:redhat:enterprise_linux:5
cpe:/a:postgresql:postgresql84

© SecPod Technologies