-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Thu, 13 May 2004 11:00:07 +0200 Source: postgresql Binary: libpgtcl postgresql pgaccess odbc-postgresql libpgperl postgresql-client libecpg3 postgresql-contrib postgresql-dev postgresql-doc python-pygresql libpgsql2 Architecture: sparc Version: 7.2.1-2woody5 Distribution: stable-security Urgency: low Maintainer: Debian/SPARC Build Daemon Changed-By: Martin Pitt Description: libecpg3 - Shared library libecpg.so.3 for PostgreSQL libpgperl - Perl modules for PostgreSQL. libpgsql2 - Shared library libpq.so.2 for PostgreSQL libpgtcl - Tcl/Tk library and front-end for PostgreSQL. odbc-postgresql - ODBC support for PostgreSQL pgaccess - Tk/Tcl front-end for PostgreSQL database postgresql - Object-relational SQL database, descended from POSTGRES. postgresql-client - Front-end programs for PostgreSQL postgresql-contrib - Additional facilities for PostgreSQL postgresql-dev - Header files for libpq (postgresql library) python-pygresql - PostgreSQL module for Python Changes: postgresql (7.2.1-2woody5) stable-security; urgency=low . * Fixed buffer overflow in ODBC driver (src/interfaces/odbc/): added parameter for target buffer size to make_string() to prevent buffer overflows and corrected all calls to it. This fixes #247306 for woody (bug was already closed with the upload to sid). . With previous versions it was possible to crash (and possibly exploit) e. g. apache if a PHP script connected to a ODBC database with very long credential strings (DSN, username, password, etc.). . Other parts of postgresql are not affected. Files: a2aa1d755dca60aa056bbe18bd9049d8 1671358 misc optional postgresql_7.2.1-2woody5_sparc.deb e1152b9f142201d901bd847ff6f316c1 288574 misc optional postgresql-client_7.2.1-2woody5_sparc.deb 5e1788307a029b0f1629d971810c83e4 501866 devel optional postgresql-dev_7.2.1-2woody5_sparc.deb bdae3180c820e7d086d67352a58525aa 67914 libs optional libpgsql2_7.2.1-2woody5_sparc.deb 5dbd7896cbab66c6baa924b7a8d19db4 30666 libs optional libecpg3_7.2.1-2woody5_sparc.deb d3fe7fb157e567c06d92077969d247c4 54776 libs optional libpgtcl_7.2.1-2woody5_sparc.deb 4138202014e9adb5a3437d43af8c4489 64384 libs optional libpgperl_7.2.1-2woody5_sparc.deb 24a3c01b545b17d10ebc36eb08729784 424956 misc optional pgaccess_7.2.1-2woody5_sparc.deb a529b352731287162f738fbca8f46fbb 370862 misc optional postgresql-contrib_7.2.1-2woody5_sparc.deb cb92d1b4bdf8f9eef11a01ab85182253 62130 misc optional python-pygresql_7.2.1-2woody5_sparc.deb 01bbde0036b1a633f3e0e7eb6efbf507 232342 libs optional odbc-postgresql_7.2.1-2woody5_sparc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFAo56QW5ql+IAeqTIRAnqRAJ9VfJa/aO2LBAgrKzormHacJwl8kgCdGibO MLjINjYfA8l6cHXTyekzgqI= =YLrF -----END PGP SIGNATURE-----