Errata ID | 475 |
---|---|
Date | 2017-08-30 |
Source package | postgresql-9.1 |
Fixed in version | 9.1.24-0.13.201708211620 |
Description | This update addresses the following issues: * Restrict visibility of pg_user_mappings.umoptions, to protect passwords stored as user mapping options (CVE-2017-7486) * In some authentication methods empty passwords were accepted (CVE-2017-7546) * User mappings could leak data to unprivileged users (CVE-2017-7547) |
Additional notes | |
CVE ID | CVE-2017-7486 CVE-2017-7546 CVE-2017-7547 |
UCS Bug number | #45236 |