Re: [ANNOUNCE] CRITICAL RELEASE: Minor Releases to Fix DoS

From: Simon Riggs <simon(at)2ndquadrant(dot)com>
To: Magnus Hagander <mha(at)sollentuna(dot)net>, "Marc G(dot) Fournier" <scrappy(at)postgresql(dot)org>
Cc: pgsql-www(at)postgresql(dot)org
Subject: Re: [ANNOUNCE] CRITICAL RELEASE: Minor Releases to Fix DoS
Date: 2006-01-09 09:29:12
Message-ID: 1136798952.21025.344.camel@localhost.localdomain
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-announce pgsql-general pgsql-www

On Mon, 2006-01-09 at 02:33 -0400, Marc G. Fournier wrote:
> PostgreSQL patch versions 8.1.2, 8.0.6, 7.4.11 and 7.3.13 are available
> today. The fixes in the 8.1 and 8.0 branches are critical, especially for
> Windows users, and users of these branches are urged to update at their
> earliest opportunity.
>
> One critical fix repairs a denial-of-service vulnerability: on Windows
> only, the postmaster will exit if too many connection requests arrive
> simultaneously. This does not affect existing database connections, but
> will prevent new connections from being established until the postmaster
> is manually restarted.

> The Common Vulnerabilities and Exposures (CVE)
> project has assigned the name CVE-2006-0105 to this issue.

No they haven't: there is no such CVE number assigned, nor is there one
pending - I just checked. (The numbers don't go that high yet).

[I was looking to update the Security page, but can't find the
appropriate refs.]

Best Regards, Simon Riggs

In response to

Browse pgsql-announce by date

  From Date Subject
Next Message David Fetter 2006-01-09 09:29:33 == PostgreSQL Weekly News - January 08 2006 ==
Previous Message Marc G. Fournier 2006-01-09 06:33:40 CRITICAL RELEASE: Minor Releases to Fix DoS Vulnerability

Browse pgsql-general by date

  From Date Subject
Next Message Markus Bertheau 2006-01-09 09:30:08 Re: [ANNOUNCE] CRITICAL RELEASE: Minor Releases to Fix DoS
Previous Message Magnus Hagander 2006-01-09 09:25:57 Re: Unregister Windows Service pg_ctl error

Browse pgsql-www by date

  From Date Subject
Next Message Markus Bertheau 2006-01-09 09:30:08 Re: [ANNOUNCE] CRITICAL RELEASE: Minor Releases to Fix DoS
Previous Message Magnus Hagander 2006-01-09 08:35:28 Re: Release Announcement News Item -- please read