Subject: CVS commit: pkgsrc
From: Adam Ciarcinski
Date: 2013-04-04 23:08:38
Message id: 20130404210838.8953C175DD@cvs.netbsd.org

Log Message:
The PostgreSQL Global Development Group has released a security update to all \ 
current versions of the PostgreSQL database system, including versions 9.2.4, \ 
9.1.9, 9.0.13, and 8.4.17. This update fixes a high-exposure security \ 
vulnerability in versions 9.0 and later. All users of the affected versions are \ 
strongly urged to apply the update immediately.

A major security issue fixed in this release, CVE-2013-1899, makes it possible \ 
for a connection request containing a database name that begins with \ 
"-" to be crafted that can damage or destroy files within a server's \ 
data directory. Anyone with access to the port the PostgreSQL server listens on \ 
can initiate this request.

Two lesser security fixes are also included in this release: CVE-2013-1900, \ 
wherein random numbers generated by contrib/pgcrypto functions may be easy for \ 
another database user to guess, and CVE-2013-1901, which mistakenly allows an \ 
unprivileged user to run commands that could interfere with in-progress backups. \ 
Finally, this release fixes two security issues with the graphical installers \ 
for Linux and Mac OS X: insecure passing of superuser passwords to a script, \ 
CVE-2013-1903 and the use of predictable filenames in /tmp CVE-2013-1902.

Files:
RevisionActionfile
1.26modifypkgsrc/databases/postgresql84/Makefile.common
1.25modifypkgsrc/databases/postgresql84/distinfo
1.19modifypkgsrc/databases/postgresql84-client/PLIST
1.15modifypkgsrc/databases/postgresql84-server/PLIST
1.24modifypkgsrc/databases/postgresql90/Makefile.common
1.17modifypkgsrc/databases/postgresql90/distinfo
1.15modifypkgsrc/databases/postgresql90-docs/PLIST
1.12modifypkgsrc/databases/postgresql90-server/PLIST
1.14modifypkgsrc/databases/postgresql91/Makefile.common
1.14modifypkgsrc/databases/postgresql91/distinfo
1.11modifypkgsrc/databases/postgresql91-docs/PLIST
1.7modifypkgsrc/databases/postgresql91-server/PLIST
1.5modifypkgsrc/databases/postgresql92/Makefile.common
1.4modifypkgsrc/databases/postgresql92/distinfo
1.4modifypkgsrc/databases/postgresql92-client/PLIST
1.4modifypkgsrc/databases/postgresql92-docs/PLIST
1.3modifypkgsrc/databases/postgresql92-server/PLIST
1.2modifypkgsrc/databases/postgresql92/patches/patch-contrib_dblink_dblink.c
1.1.1.1removepkgsrc/databases/jdbc-postgresql83/DESCR
1.4removepkgsrc/databases/jdbc-postgresql83/Makefile
1.2removepkgsrc/databases/jdbc-postgresql83/PLIST
1.2removepkgsrc/databases/jdbc-postgresql83/distinfo
1.1.1.1removepkgsrc/databases/postgresql83/DESCR
1.8removepkgsrc/databases/postgresql83/Makefile
1.29removepkgsrc/databases/postgresql83/Makefile.common
1.1.1.1removepkgsrc/databases/postgresql83/PLIST
1.28removepkgsrc/databases/postgresql83/distinfo
1.6removepkgsrc/databases/postgresql83/options.mk
1.1.1.1removepkgsrc/databases/postgresql83-client/DESCR
1.31removepkgsrc/databases/postgresql83-client/Makefile
1.25removepkgsrc/databases/postgresql83-client/PLIST
1.7removepkgsrc/databases/postgresql83-client/buildlink3.mk
1.1.1.1removepkgsrc/databases/postgresql83-plperl/DESCR
1.1.1.1removepkgsrc/databases/postgresql83-plperl/MESSAGE
1.22removepkgsrc/databases/postgresql83-plperl/Makefile
1.3removepkgsrc/databases/postgresql83-plperl/PLIST
1.1.1.1removepkgsrc/databases/postgresql83-plpython/DESCR
1.1.1.1removepkgsrc/databases/postgresql83-plpython/MESSAGE
1.18removepkgsrc/databases/postgresql83-plpython/Makefile
1.3removepkgsrc/databases/postgresql83-plpython/PLIST
1.1.1.1removepkgsrc/databases/postgresql83-pltcl/DESCR
1.1.1.1removepkgsrc/databases/postgresql83-pltcl/MESSAGE
1.14removepkgsrc/databases/postgresql83-pltcl/Makefile
1.3removepkgsrc/databases/postgresql83-pltcl/PLIST
1.1.1.1removepkgsrc/databases/postgresql83-server/DEINSTALL
1.1.1.1removepkgsrc/databases/postgresql83-server/DESCR
1.3removepkgsrc/databases/postgresql83-server/MESSAGE
1.25removepkgsrc/databases/postgresql83-server/Makefile
1.18removepkgsrc/databases/postgresql83-server/PLIST
1.6removepkgsrc/databases/postgresql83-server/files/pgsql.sh
1.3removepkgsrc/databases/postgresql83-uuid/Makefile
1.1.1.1removepkgsrc/databases/postgresql83/files/GNUmakefile.libpq
1.1.1.1removepkgsrc/databases/postgresql83/files/dynloader-ltdl.h
1.3removepkgsrc/databases/postgresql83/patches/patch-aa
1.5removepkgsrc/databases/postgresql83/patches/patch-ab
1.1.1.1removepkgsrc/databases/postgresql83/patches/patch-ac
1.5removepkgsrc/databases/postgresql83/patches/patch-ad
1.1.1.1removepkgsrc/databases/postgresql83/patches/patch-af
1.1.1.1removepkgsrc/databases/postgresql83/patches/patch-ag
1.1.1.1removepkgsrc/databases/postgresql83/patches/patch-ah
1.1.1.1removepkgsrc/databases/postgresql83/patches/patch-ai
1.2removepkgsrc/databases/postgresql83/patches/patch-ba
1.1removepkgsrc/databases/postgresql83/patches/patch-src_interfaces_ecpg_ecpglib_Makefile
1.1removepkgsrc/databases/postgresql83/patches/patch-src_makefiles_Makefile.solaris
1.1removepkgsrc/databases/postgresql83/patches/patch-src_pl_plperl_plperl.h
1.1removepkgsrc/databases/postgresql83/patches/patch-src_pl_plpgsql_src_Makefile