Subject: CVS commit: pkgsrc/databases
From: Adam Ciarcinski
Date: 2015-10-10 12:22:20
Message id: 20151010102221.06ADC98@cvs.netbsd.org

Log Message:
Changes 9.4.5:
Two security issues have been fixed in this release which affect users of \ 
specific PostgreSQL features:

CVE-2015-5289: json or jsonb input values constructed from arbitrary user input \ 
can crash the PostgreSQL server and cause a denial of service.

CVE-2015-5288: The crypt() function included with the optional pgCrypto \ 
extension could be exploited to read a few additional bytes of memory. No \ 
working exploit for this issue has been developed.

Files:
RevisionActionfile
1.6modifypkgsrc/databases/postgresql94/Makefile.common
1.7modifypkgsrc/databases/postgresql94/distinfo
1.6modifypkgsrc/databases/postgresql94-docs/PLIST
1.3modifypkgsrc/databases/postgresql94-server/PLIST
1.2modifypkgsrc/databases/postgresql94/patches/patch-src_Makefile.global.in