<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="899579e6feb8563f5e72bf79a2b3768c"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="2472">
  <id>dbg111-postgresql</id>
  <title>postgresql: security update to fix four vulnerabilities</title>
  <release>openSUSE 11.1 DEBUGINFO</release>
  <issued date="1274746026"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=607778" id="607778" title="bug number 607778" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=588996" id="588996" title="bug number 588996" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=605845" id="605845" title="bug number 605845" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=605926" id="605926" title="bug number 605926" type="bugzilla"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1975" id="CVE-2010-1975" title="CVE-2010-1975" type="cve"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1169" id="CVE-2010-1169" title="CVE-2010-1169" type="cve"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1170" id="CVE-2010-1170" title="CVE-2010-1170" type="cve"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0733" id="CVE-2010-0733" title="CVE-2010-0733" type="cve"/>
  </references>
  <description>This update of postgresql was pblished to fix several minor
security vulnerabilities:
- CVE-2010-1975: postgresql does not properly check
  privileges during certain RESET ALL operations, which
  allows remote authenticated users to remove arbitrary
  parameter settings.
- CVE-2010-1170: The PL/Tcl implementation in postgresql
  loads Tcl code from the pltcl_modules table regardless of
  the table's ownership and permissions, which allows
  remote authenticated users, with database-creation
  privileges, to execute arbitrary Tcl code.
- CVE-2010-1169: Postgresql does not properly restrict
  PL/perl procedures, which allows remote authenticated
  users, with database-creation privileges, to execute
  arbitrary Perl code via a crafted script.
- CVE-2010-0733: An integer overflow in postgresql allows
  remote authenticated users to crash the daemon via a
  SELECT statement.
</description>
  <pkglist>
    <collection>
        <package name="postgresql-debuginfo" arch="i586" version="8.3.11" release="0.1.1">
          <filename>postgresql-debuginfo-8.3.11-0.1.1.i586.rpm</filename>
        </package>
        <package name="postgresql-debuginfo" arch="ppc" version="8.3.11" release="0.1.1">
          <filename>postgresql-debuginfo-8.3.11-0.1.1.ppc.rpm</filename>
        </package>
        <package name="postgresql-debuginfo" arch="x86_64" version="8.3.11" release="0.1.1">
          <filename>postgresql-debuginfo-8.3.11-0.1.1.x86_64.rpm</filename>
        </package>
        <package name="postgresql-debugsource" arch="i586" version="8.3.11" release="0.1.1">
          <filename>postgresql-debugsource-8.3.11-0.1.1.i586.rpm</filename>
        </package>
        <package name="postgresql-debugsource" arch="ppc" version="8.3.11" release="0.1.1">
          <filename>postgresql-debugsource-8.3.11-0.1.1.ppc.rpm</filename>
        </package>
        <package name="postgresql-debugsource" arch="x86_64" version="8.3.11" release="0.1.1">
          <filename>postgresql-debugsource-8.3.11-0.1.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
