First published: Thu Aug 23 2018(Updated: )
PostgreSQL is an advanced object-relational database management system (DBMS).<br>The following packages have been upgraded to a later upstream version: postgresql (9.2.24). (BZ#1612667)<br>Security Fix(es):<br><li> postgresql: Certain host connection parameters defeat client-side security defenses (CVE-2018-10915)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Red Hat would like to thank the PostgreSQL project for reporting this issue. Upstream acknowledges Andrew Krasichkov as the original reporter.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/postgresql | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-contrib | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-debuginfo | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-debuginfo | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-devel | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-devel | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-docs | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-libs | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-libs | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-plperl | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-plpython | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-pltcl | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-server | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-static | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-static | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-test | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-upgrade | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-contrib | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-docs | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-plperl | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-plpython | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-pltcl | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-server | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-test | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-upgrade | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-contrib | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-debuginfo | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-devel | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-docs | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-libs | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-plperl | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-plpython | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-pltcl | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-server | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-static | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-test | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql-upgrade | <9.2.24-1.el7_5 | 9.2.24-1.el7_5 |
redhat/postgresql | <9.2.24-1.el7_5.aa | 9.2.24-1.el7_5.aa |
redhat/postgresql-contrib | <9.2.24-1.el7_5.aa | 9.2.24-1.el7_5.aa |
redhat/postgresql-debuginfo | <9.2.24-1.el7_5.aa | 9.2.24-1.el7_5.aa |
redhat/postgresql-devel | <9.2.24-1.el7_5.aa | 9.2.24-1.el7_5.aa |
redhat/postgresql-docs | <9.2.24-1.el7_5.aa | 9.2.24-1.el7_5.aa |
redhat/postgresql-libs | <9.2.24-1.el7_5.aa | 9.2.24-1.el7_5.aa |
redhat/postgresql-plperl | <9.2.24-1.el7_5.aa | 9.2.24-1.el7_5.aa |
redhat/postgresql-plpython | <9.2.24-1.el7_5.aa | 9.2.24-1.el7_5.aa |
redhat/postgresql-pltcl | <9.2.24-1.el7_5.aa | 9.2.24-1.el7_5.aa |
redhat/postgresql-server | <9.2.24-1.el7_5.aa | 9.2.24-1.el7_5.aa |
redhat/postgresql-static | <9.2.24-1.el7_5.aa | 9.2.24-1.el7_5.aa |
redhat/postgresql-test | <9.2.24-1.el7_5.aa | 9.2.24-1.el7_5.aa |
redhat/postgresql-upgrade | <9.2.24-1.el7_5.aa | 9.2.24-1.el7_5.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2018:2557 is classified as important.
To fix RHSA-2018:2557, upgrade to PostgreSQL version 9.2.24-1.el7_5.
RHSA-2018:2557 addresses security issues related to host connection parameters that may defeat client-side security measures.
Affected versions include all versions up to 9.2.24-1.el7_5.
Packages impacted by RHSA-2018:2557 include postgresql, postgresql-contrib, postgresql-devel, and others related to the PostgreSQL ecosystem.