DSA-577-1 postgresql -- insecure temporary file

Related Vulnerabilities: CVE-2004-0977  

Trustix Security Engineers identified insecure temporary file creation in a script included in the postgresql suite, an object-relational SQL database. This could lead an attacker to trick a user to overwrite arbitrary files he has write access to. For the stable distribution (woody) this problem has been fixed in version 7.2.1-2woody6. For the unstable distribution (sid) this problem has been fixed in version 7.4.6-1. We recommend that you upgrade your postgresql packages.

Debian Security Advisory

DSA-577-1 postgresql -- insecure temporary file

Date Reported:
29 Oct 2004
Affected Packages:
postgresql
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 278336.
In Mitre's CVE dictionary: CVE-2004-0977.
More information:

Trustix Security Engineers identified insecure temporary file creation in a script included in the postgresql suite, an object-relational SQL database. This could lead an attacker to trick a user to overwrite arbitrary files he has write access to.

For the stable distribution (woody) this problem has been fixed in version 7.2.1-2woody6.

For the unstable distribution (sid) this problem has been fixed in version 7.4.6-1.

We recommend that you upgrade your postgresql packages.

Fixed in:

Debian GNU/Linux 3.0 (woody)

Source:
http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6.dsc
http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6.diff.gz
http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1.orig.tar.gz
Architecture-independent component:
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-doc_7.2.1-2woody6_all.deb
Alpha:
http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_alpha.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_alpha.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_alpha.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_alpha.deb
http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_alpha.deb
http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_alpha.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_alpha.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_alpha.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_alpha.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_alpha.deb
http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_arm.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_arm.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_arm.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_arm.deb
http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_arm.deb
http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_arm.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_arm.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_arm.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_arm.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_arm.deb
http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_i386.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_i386.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_i386.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_i386.deb
http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_i386.deb
http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_i386.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_i386.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_i386.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_i386.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_i386.deb
http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_ia64.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_ia64.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_ia64.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_ia64.deb
http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_ia64.deb
http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_ia64.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_ia64.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_ia64.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_ia64.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_ia64.deb
http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_hppa.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_hppa.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_hppa.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_hppa.deb
http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_hppa.deb
http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_hppa.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_hppa.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_hppa.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_hppa.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_hppa.deb
http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_m68k.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_m68k.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_m68k.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_m68k.deb
http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_m68k.deb
http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_m68k.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_m68k.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_m68k.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_m68k.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_m68k.deb
http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_mips.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_mips.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_mips.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_mips.deb
http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_mips.deb
http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_mips.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_mips.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_mips.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_mips.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_mips.deb
http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_mipsel.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_mipsel.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_mipsel.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_mipsel.deb
http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_mipsel.deb
http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_mipsel.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_mipsel.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_mipsel.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_mipsel.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_mipsel.deb
http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_powerpc.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_powerpc.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_powerpc.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_powerpc.deb
http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_powerpc.deb
http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_powerpc.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_powerpc.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_powerpc.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_powerpc.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_powerpc.deb
http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_s390.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_s390.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_s390.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_s390.deb
http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_s390.deb
http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_s390.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_s390.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_s390.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_s390.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_s390.deb
http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/p/postgresql/libecpg3_7.2.1-2woody6_sparc.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgperl_7.2.1-2woody6_sparc.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgsql2_7.2.1-2woody6_sparc.deb
http://security.debian.org/pool/updates/main/p/postgresql/libpgtcl_7.2.1-2woody6_sparc.deb
http://security.debian.org/pool/updates/main/p/postgresql/odbc-postgresql_7.2.1-2woody6_sparc.deb
http://security.debian.org/pool/updates/main/p/postgresql/pgaccess_7.2.1-2woody6_sparc.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql_7.2.1-2woody6_sparc.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-client_7.2.1-2woody6_sparc.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-contrib_7.2.1-2woody6_sparc.deb
http://security.debian.org/pool/updates/main/p/postgresql/postgresql-dev_7.2.1-2woody6_sparc.deb
http://security.debian.org/pool/updates/main/p/postgresql/python-pygresql_7.2.1-2woody6_sparc.deb

MD5 checksums of the listed files are available in the original advisory.