Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  NEWS  community  lists  Wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Password Recovery Resources on the Net
[<prev] [next>] [<thread-prev] [thread-next>] [month] [year] [list]
Date: Wed, 9 Sep 2009 16:23:15 +0200
From: Tomas Hoger <thoger@...hat.com>
To: oss-security@...ts.openwall.com
Cc: "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE Request -- PostgreSQL

On Wed, 09 Sep 2009 16:08:10 +0200 Jan Lieskovsky <jlieskov@...hat.com>
wrote:

>    PostgreSQL upstream is on their security page
> mentioning three security issues, which lack CVE ids:
> 
> http://www.postgresql.org/support/security.html

Just a note: upstream page currently says the second issue is related
to CVE-2007-2138, but our maintainer also active upstream reports it
should say CVE-2007-6600.

https://bugzilla.redhat.com/show_bug.cgi?id=522085#c1

I can't confirm either atm, so just a heads-up to avoid possible
confusion related to CVE wording.

-- 
Tomas Hoger / Red Hat Security Response Team

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ