← Back to team overview

desktop-packages team mailing list archive

[Bug 1457093] [NEW] New upstream microreleases 9.1.16, 9.3.7, 9.4.2

 

*** This bug is a security vulnerability ***

Public security bug reported:

PostgreSQL will push out new microreleases on Friday, 2015-05-22. The
tarballs for the updates are not public yet, but the fixes are visible
in the upstream git, so there's no need to treat this as embargoed, but
there should still be a coordinated release. These fix a couple of
security issues, as well as the usual set of bug fixes.

** Affects: postgresql-9.1 (Ubuntu)
     Importance: Undecided
         Status: Invalid

** Affects: postgresql-9.3 (Ubuntu)
     Importance: Undecided
         Status: Invalid

** Affects: postgresql-9.4 (Ubuntu)
     Importance: High
         Status: In Progress

** Affects: postgresql-9.1 (Ubuntu Precise)
     Importance: Undecided
         Status: New

** Affects: postgresql-9.1 (Ubuntu Trusty)
     Importance: Undecided
         Status: New

** Affects: postgresql-9.3 (Ubuntu Trusty)
     Importance: Undecided
         Status: New

** Affects: postgresql-9.4 (Ubuntu Utopic)
     Importance: Undecided
         Status: New

** Affects: postgresql-9.4 (Ubuntu Vivid)
     Importance: Undecided
     Assignee: Martin Pitt (pitti)
         Status: New

** Affects: postgresql-9.4 (Ubuntu Wily)
     Importance: High
         Status: In Progress

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2015-3165

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2015-3166

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2015-3167

** Also affects: postgresql-9.3 (Ubuntu)
   Importance: Undecided
       Status: New

** Also affects: postgresql-9.4 (Ubuntu)
   Importance: Undecided
       Status: New

** Also affects: postgresql-9.1 (Ubuntu Trusty)
   Importance: Undecided
       Status: New

** Also affects: postgresql-9.3 (Ubuntu Trusty)
   Importance: Undecided
       Status: New

** Also affects: postgresql-9.4 (Ubuntu Trusty)
   Importance: Undecided
       Status: New

** Also affects: postgresql-9.1 (Ubuntu Wily)
   Importance: Undecided
       Status: New

** Also affects: postgresql-9.3 (Ubuntu Wily)
   Importance: Undecided
       Status: New

** Also affects: postgresql-9.4 (Ubuntu Wily)
   Importance: Undecided
       Status: New

** Also affects: postgresql-9.1 (Ubuntu Precise)
   Importance: Undecided
       Status: New

** Also affects: postgresql-9.3 (Ubuntu Precise)
   Importance: Undecided
       Status: New

** Also affects: postgresql-9.4 (Ubuntu Precise)
   Importance: Undecided
       Status: New

** Also affects: postgresql-9.1 (Ubuntu Utopic)
   Importance: Undecided
       Status: New

** Also affects: postgresql-9.3 (Ubuntu Utopic)
   Importance: Undecided
       Status: New

** Also affects: postgresql-9.4 (Ubuntu Utopic)
   Importance: Undecided
       Status: New

** Also affects: postgresql-9.1 (Ubuntu Vivid)
   Importance: Undecided
       Status: New

** Also affects: postgresql-9.3 (Ubuntu Vivid)
   Importance: Undecided
       Status: New

** Also affects: postgresql-9.4 (Ubuntu Vivid)
   Importance: Undecided
       Status: New

** No longer affects: postgresql-9.1 (Ubuntu Wily)

** No longer affects: postgresql-9.1 (Ubuntu Vivid)

** No longer affects: postgresql-9.1 (Ubuntu Utopic)

** Changed in: postgresql-9.1 (Ubuntu)
       Status: New => Invalid

** No longer affects: postgresql-9.3 (Ubuntu Precise)

** No longer affects: postgresql-9.3 (Ubuntu Utopic)

** No longer affects: postgresql-9.3 (Ubuntu Vivid)

** No longer affects: postgresql-9.3 (Ubuntu Wily)

** Changed in: postgresql-9.3 (Ubuntu)
       Status: New => Invalid

** No longer affects: postgresql-9.4 (Ubuntu Precise)

** No longer affects: postgresql-9.4 (Ubuntu Trusty)

** Changed in: postgresql-9.4 (Ubuntu Wily)
       Status: New => In Progress

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to postgresql-9.1 in Ubuntu.
https://bugs.launchpad.net/bugs/1457093

Title:
  New upstream microreleases 9.1.16, 9.3.7, 9.4.2

Status in postgresql-9.1 package in Ubuntu:
  Invalid
Status in postgresql-9.3 package in Ubuntu:
  Invalid
Status in postgresql-9.4 package in Ubuntu:
  In Progress
Status in postgresql-9.1 source package in Precise:
  New
Status in postgresql-9.1 source package in Trusty:
  New
Status in postgresql-9.3 source package in Trusty:
  New
Status in postgresql-9.4 source package in Utopic:
  New
Status in postgresql-9.4 source package in Vivid:
  New
Status in postgresql-9.4 source package in Wily:
  In Progress

Bug description:
  PostgreSQL will push out new microreleases on Friday, 2015-05-22. The
  tarballs for the updates are not public yet, but the fixes are visible
  in the upstream git, so there's no need to treat this as embargoed,
  but there should still be a coordinated release. These fix a couple of
  security issues, as well as the usual set of bug fixes.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/postgresql-9.1/+bug/1457093/+subscriptions


Follow ups

References