Opened 10 years ago

Closed 10 years ago

#4840 closed enhancement (fixed)

postgresql-9.3.4

Reported by: Fernando de Oliveira Owned by: ken@…
Priority: normal Milestone: 7.6
Component: BOOK Version: SVN
Severity: normal Keywords:
Cc:

Description

Change History (5)

comment:1 by ken@…, 10 years ago

Does anybody have any idea if this fixes CVE-2014-067 ? I spent some time looking around yesterday, but made no progress : Arch (or perhaps its wiki) thinks it was fixed in 9.3.3 (!), debian claim it is fixed in 9.3.4-1 but I have not managed to locate their source on a local mirror. The mailing list about this seemed to indicate some uncertainty about the correct way to fix this, then apparently went silent.

comment:2 by ken@…, 10 years ago

Owner: changed from blfs-book@… to ken@…

comment:3 by ken@…, 10 years ago

Status: newassigned

comment:4 by ken@…, 10 years ago

Found postgresql git at git://git.postgresql.org/git/postgresql.git - a first attempt at fixing this went in on 29th March which is after 9.3.4, but was then reverted on the same day because about half the build-farm members use too-long directory names, strongly suggesting that approach is a dead end.

So for now the warning must remain.

comment:5 by ken@…, 10 years ago

Resolution: fixed
Status: assignedclosed

Fixed at r12945.

Note: See TracTickets for help on using tickets.