From 4cab124a0b1b7504e50fd02357022cdad1a61865 Mon Sep 17 00:00:00 2001 From: Gustavo Zacarias Date: Thu, 8 Oct 2015 15:59:12 -0300 Subject: postgresql: security bump to version 9.4.5 Fixes: CVE-2015-5289: json or jsonb input values constructed from arbitrary user input can crash the PostgreSQL server and cause a denial of service. CVE-2015-5288: The crypt() function included with the optional pgCrypto extension could be exploited to read a few additional bytes of memory. No working exploit for this issue has been developed. sparc build fix patch upstream so drop it. Signed-off-by: Gustavo Zacarias Reviewed-by: Vicente Olivert Riera Tested-by: Vicente Olivert Riera Signed-off-by: Thomas Petazzoni --- package/postgresql/postgresql.hash | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'package/postgresql/postgresql.hash') diff --git a/package/postgresql/postgresql.hash b/package/postgresql/postgresql.hash index 5f415af535..97bb56d92f 100644 --- a/package/postgresql/postgresql.hash +++ b/package/postgresql/postgresql.hash @@ -1,2 +1,2 @@ -# From https://ftp.postgresql.org/pub/source/v9.4.4/postgresql-9.4.4.tar.bz2.sha256 -sha256 538ed99688d6fdbec6fd166d1779cf4588bf2f16c52304e5ef29f904c43b0013 postgresql-9.4.4.tar.bz2 +# From https://ftp.postgresql.org/pub/source/v9.4.5/postgresql-9.4.5.tar.bz2.sha256 +sha256 b87c50c66b6ea42a9712b5f6284794fabad0616e6ae420cf0f10523be6d94a39 postgresql-9.4.5.tar.bz2 -- cgit v1.2.3