From owner-cvs-ports@FreeBSD.ORG Mon Feb 5 15:41:41 2007 Return-Path: X-Original-To: cvs-ports@FreeBSD.org Delivered-To: cvs-ports@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id D385116A57A; Mon, 5 Feb 2007 15:41:41 +0000 (UTC) (envelope-from girgen@FreeBSD.org) Received: from repoman.freebsd.org (repoman.freebsd.org [69.147.83.41]) by mx1.freebsd.org (Postfix) with ESMTP id C46F713C481; Mon, 5 Feb 2007 15:41:41 +0000 (UTC) (envelope-from girgen@FreeBSD.org) Received: from repoman.freebsd.org (localhost [127.0.0.1]) by repoman.freebsd.org (8.13.6/8.13.6) with ESMTP id l15FffMA069923; Mon, 5 Feb 2007 15:41:41 GMT (envelope-from girgen@repoman.freebsd.org) Received: (from girgen@localhost) by repoman.freebsd.org (8.13.6/8.13.4/Submit) id l15FffYs069921; Mon, 5 Feb 2007 15:41:41 GMT (envelope-from girgen) Message-Id: <200702051541.l15FffYs069921@repoman.freebsd.org> From: Palle Girgensohn Date: Mon, 5 Feb 2007 15:41:41 +0000 (UTC) To: ports-committers@FreeBSD.org, cvs-ports@FreeBSD.org, cvs-all@FreeBSD.org X-FreeBSD-CVS-Branch: HEAD Cc: Subject: cvs commit: ports/databases/postgresql82-server Makefile distinfo X-BeenThere: cvs-ports@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: CVS commit messages for the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 05 Feb 2007 15:41:42 -0000 girgen 2007-02-05 15:41:41 UTC FreeBSD ports repository Modified files: databases/postgresql82-server Makefile distinfo Log: Update PostgreSQL with, amongst other things, two security fixes: A vulnerability allows suppressing the normal checks that a SQL function returns the data type it's declared to do. These errors can easily be exploited to cause a backend crash, and in principle might be used to read database content that the user should not be able to access. [CVE-2007-0555] A vulnerability involving changing the data type of a table column can easily be exploited to cause a backend crash, and in principle might be used to read database content that the user should not be able to access. [CVE-2007-0556] The release includes a set of other fixes as well. Please see the release information at http://www.postgresql.org/docs/8.2/static/release-8-2-2.html Security: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0555 Security: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0556 Revision Changes Path 1.164 +1 -1 ports/databases/postgresql82-server/Makefile 1.53 +12 -12 ports/databases/postgresql82-server/distinfo