[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3851-1 postgresql-9.4 -- postgresql-9.4

ID: oval:org.secpod.oval:def:602879Date: (C)2017-05-17   (M)2023-02-06
Class: PATCHFamily: unix




Several vulnerabilities have been found in the PostgreSQL database system: CVE-2017-7484 Robert Haas discovered that some selectivity estimators did not validate user privileges which could result in information disclosure. CVE-2017-7485 Daniel Gustafsson discovered that the PGREQUIRESSL environment variable did no longer enforce a TLS connection. CVE-2017-7486 Andrew Wheelwright discovered that user mappings were insufficiently restricted.

Platform:
Debian 8.x
Product:
postgresql-9.4
Reference:
DSA-3851-1
CVE-2017-7484
CVE-2017-7485
CVE-2017-7486
CVE    3
CVE-2017-7486
CVE-2017-7485
CVE-2017-7484
CPE    2
cpe:/o:debian:debian_linux:8.x
cpe:/a:postgresql:postgresql:9.4

© SecPod Technologies