-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Thu, 13 May 2004 11:00:07 +0200 Source: postgresql Binary: libpgtcl postgresql pgaccess odbc-postgresql libpgperl postgresql-client libecpg3 postgresql-contrib postgresql-dev postgresql-doc python-pygresql libpgsql2 Architecture: hppa Version: 7.2.1-2woody5 Distribution: stable-security Urgency: low Maintainer: Debian/HPPA non-US Build Daemon Changed-By: Martin Pitt Description: libecpg3 - Shared library libecpg.so.3 for PostgreSQL libpgperl - Perl modules for PostgreSQL. libpgsql2 - Shared library libpq.so.2 for PostgreSQL libpgtcl - Tcl/Tk library and front-end for PostgreSQL. odbc-postgresql - ODBC support for PostgreSQL pgaccess - Tk/Tcl front-end for PostgreSQL database postgresql - Object-relational SQL database, descended from POSTGRES. postgresql-client - Front-end programs for PostgreSQL postgresql-contrib - Additional facilities for PostgreSQL postgresql-dev - Header files for libpq (postgresql library) python-pygresql - PostgreSQL module for Python Changes: postgresql (7.2.1-2woody5) stable-security; urgency=low . * Fixed buffer overflow in ODBC driver (src/interfaces/odbc/): added parameter for target buffer size to make_string() to prevent buffer overflows and corrected all calls to it. This fixes #247306 for woody (bug was already closed with the upload to sid). . With previous versions it was possible to crash (and possibly exploit) e. g. apache if a PHP script connected to a ODBC database with very long credential strings (DSN, username, password, etc.). . Other parts of postgresql are not affected. Files: a65d21521c62acbd68aac0d4c6f7fbba 1826206 misc optional postgresql_7.2.1-2woody5_hppa.deb 22627ab09d6bc312971e1642da7552e5 304346 misc optional postgresql-client_7.2.1-2woody5_hppa.deb 937cbc718d73fbeb411d65ac61dfb124 523818 devel optional postgresql-dev_7.2.1-2woody5_hppa.deb f84f7f4e08d1ed05a1af78d47682d802 76664 libs optional libpgsql2_7.2.1-2woody5_hppa.deb 2f0bd2c4b52e5af66422ce5efdeeb530 33580 libs optional libecpg3_7.2.1-2woody5_hppa.deb ac8daf782c12df66f42e68a0d753ddf7 65402 libs optional libpgtcl_7.2.1-2woody5_hppa.deb a9bd3a46360200a6554f95dbaa7ff94c 70262 libs optional libpgperl_7.2.1-2woody5_hppa.deb b81a0c52857b657f75613163d56a0502 425062 misc optional pgaccess_7.2.1-2woody5_hppa.deb a21fac74c5f94b8d287677c7f29ebfb0 371684 misc optional postgresql-contrib_7.2.1-2woody5_hppa.deb e4eaa35bf81244d341ab822f954e9d39 65812 misc optional python-pygresql_7.2.1-2woody5_hppa.deb 1410ba2d32628cfbaf3d87c3be389e1d 254342 libs optional odbc-postgresql_7.2.1-2woody5_hppa.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFAo55wW5ql+IAeqTIRAt4eAKCXb/8LlDohriB4M/mzNU7CvuKHcwCfYrsg 5xE7RD7gulNXAOAVWj8qkXE= =qufu -----END PGP SIGNATURE-----