From owner-cvs-ports@FreeBSD.ORG Mon Feb 5 15:41:25 2007 Return-Path: X-Original-To: cvs-ports@FreeBSD.org Delivered-To: cvs-ports@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id D708E16A411; Mon, 5 Feb 2007 15:41:25 +0000 (UTC) (envelope-from girgen@FreeBSD.org) Received: from repoman.freebsd.org (repoman.freebsd.org [69.147.83.41]) by mx1.freebsd.org (Postfix) with ESMTP id C6C5A13C478; Mon, 5 Feb 2007 15:41:25 +0000 (UTC) (envelope-from girgen@FreeBSD.org) Received: from repoman.freebsd.org (localhost [127.0.0.1]) by repoman.freebsd.org (8.13.6/8.13.6) with ESMTP id l15FfP5m069658; Mon, 5 Feb 2007 15:41:25 GMT (envelope-from girgen@repoman.freebsd.org) Received: (from girgen@localhost) by repoman.freebsd.org (8.13.6/8.13.4/Submit) id l15FfP2d069657; Mon, 5 Feb 2007 15:41:25 GMT (envelope-from girgen) Message-Id: <200702051541.l15FfP2d069657@repoman.freebsd.org> From: Palle Girgensohn Date: Mon, 5 Feb 2007 15:41:25 +0000 (UTC) To: ports-committers@FreeBSD.org, cvs-ports@FreeBSD.org, cvs-all@FreeBSD.org X-FreeBSD-CVS-Branch: HEAD Cc: Subject: cvs commit: ports/databases/postgresql80-server Makefile distinfo X-BeenThere: cvs-ports@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: CVS commit messages for the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 05 Feb 2007 15:41:26 -0000 girgen 2007-02-05 15:41:25 UTC FreeBSD ports repository Modified files: databases/postgresql80-server Makefile distinfo Log: Update PostgreSQL with, amongst other things, two security fixes: A vulnerability allows suppressing the normal checks that a SQL function returns the data type it's declared to do. These errors can easily be exploited to cause a backend crash, and in principle might be used to read database content that the user should not be able to access. [CVE-2007-0555] A vulnerability involving changing the data type of a table column can easily be exploited to cause a backend crash, and in principle might be used to read database content that the user should not be able to access. [CVE-2007-0556] The release includes a set of other fixes as well. Please see the release information at http://www.postgresql.org/docs/8.0/static/release.html#RELEASE-8-0-11 Security: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0555 Security: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0556 Revision Changes Path 1.161 +1 -1 ports/databases/postgresql80-server/Makefile 1.55 +12 -12 ports/databases/postgresql80-server/distinfo