Updated mod_auth_pgsql packages that fix format string security issues are
now available for Red Hat Enterprise Linux 3 and 4.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
The mod_auth_pgsql package is an httpd module that allows user
authentication against information stored in a PostgreSQL database.
Several format string flaws were found in the way mod_auth_pgsql logs
information. It may be possible for a remote attacker to execute arbitrary
code as the 'apache' user if mod_auth_pgsql is used for user
authentication. The Common Vulnerabilities and Exposures project assigned
the name CVE-2005-3656 to this issue.
Please note that this issue only affects servers which have mod_auth_pgsql
installed and configured to perform user authentication against a
PostgreSQL database.
All users of mod_auth_pgsql should upgrade to these updated packages, which
contain a backported patch to resolve this issue.
This issue does not affect the mod_auth_pgsql package supplied with Red Hat
Enterprise Linux 2.1.
Red Hat would like to thank iDefense for reporting this issue.
| Red Hat Desktop (v. 3) |
|
| SRPMS: |
| mod_auth_pgsql-2.0.1-4.ent.1.src.rpm |
78d123ce4dd88d2b473f3def9d1f78d8 |
| |
| IA-32: |
| mod_auth_pgsql-2.0.1-4.ent.1.i386.rpm |
416d662759b7e9a6cac6db24813cadf9 |
| |
| x86_64: |
| mod_auth_pgsql-2.0.1-4.ent.1.x86_64.rpm |
cb2bd4600e4fab1ffc7e2b1fbb2a6dfb |
| |
| Red Hat Desktop (v. 4) |
|
| SRPMS: |
| mod_auth_pgsql-2.0.1-7.1.src.rpm |
2a46d8268d1d434ed8ec089bf83e62bd |
| |
| IA-32: |
| mod_auth_pgsql-2.0.1-7.1.i386.rpm |
19b586cf092086566de31c883b116f8f |
| |
| x86_64: |
| mod_auth_pgsql-2.0.1-7.1.x86_64.rpm |
542f993464e75b8e6370c453e1dc8c7d |
| |
| Red Hat Enterprise Linux AS (v. 3) |
|
| SRPMS: |
| mod_auth_pgsql-2.0.1-4.ent.1.src.rpm |
78d123ce4dd88d2b473f3def9d1f78d8 |
| |
| IA-32: |
| mod_auth_pgsql-2.0.1-4.ent.1.i386.rpm |
416d662759b7e9a6cac6db24813cadf9 |
| |
| IA-64: |
| mod_auth_pgsql-2.0.1-4.ent.1.ia64.rpm |
4a72fdbf3b94d7d1891e66d8465a5798 |
| |
| PPC: |
| mod_auth_pgsql-2.0.1-4.ent.1.ppc.rpm |
7b319bd7a03d74b6337b259f96950e8c |
| |
| s390: |
| mod_auth_pgsql-2.0.1-4.ent.1.s390.rpm |
c989ef09e9c107cd05e9ca4e75bbc789 |
| |
| s390x: |
| mod_auth_pgsql-2.0.1-4.ent.1.s390x.rpm |
476139795bf63306aaf2d478fb471982 |
| |
| x86_64: |
| mod_auth_pgsql-2.0.1-4.ent.1.x86_64.rpm |
cb2bd4600e4fab1ffc7e2b1fbb2a6dfb |
| |
| Red Hat Enterprise Linux AS (v. 4) |
|
| SRPMS: |
| mod_auth_pgsql-2.0.1-7.1.src.rpm |
2a46d8268d1d434ed8ec089bf83e62bd |
| |
| IA-32: |
| mod_auth_pgsql-2.0.1-7.1.i386.rpm |
19b586cf092086566de31c883b116f8f |
| |
| IA-64: |
| mod_auth_pgsql-2.0.1-7.1.ia64.rpm |
90ca4b0d4160b78edda12d3d300bc2bb |
| |
| PPC: |
| mod_auth_pgsql-2.0.1-7.1.ppc.rpm |
514eea209095325a9d0c4acb6c1a181f |
| |
| s390: |
| mod_auth_pgsql-2.0.1-7.1.s390.rpm |
9c32645c2f524537233212c532e6d0a7 |
| |
| s390x: |
| mod_auth_pgsql-2.0.1-7.1.s390x.rpm |
7eef05e02885fad7fb86485fe2b46630 |
| |
| x86_64: |
| mod_auth_pgsql-2.0.1-7.1.x86_64.rpm |
542f993464e75b8e6370c453e1dc8c7d |
| |
| Red Hat Enterprise Linux ES (v. 3) |
|
| SRPMS: |
| mod_auth_pgsql-2.0.1-4.ent.1.src.rpm |
78d123ce4dd88d2b473f3def9d1f78d8 |
| |
| IA-32: |
| mod_auth_pgsql-2.0.1-4.ent.1.i386.rpm |
416d662759b7e9a6cac6db24813cadf9 |
| |
| IA-64: |
| mod_auth_pgsql-2.0.1-4.ent.1.ia64.rpm |
4a72fdbf3b94d7d1891e66d8465a5798 |
| |
| x86_64: |
| mod_auth_pgsql-2.0.1-4.ent.1.x86_64.rpm |
cb2bd4600e4fab1ffc7e2b1fbb2a6dfb |
| |
| Red Hat Enterprise Linux ES (v. 4) |
|
| SRPMS: |
| mod_auth_pgsql-2.0.1-7.1.src.rpm |
2a46d8268d1d434ed8ec089bf83e62bd |
| |
| IA-32: |
| mod_auth_pgsql-2.0.1-7.1.i386.rpm |
19b586cf092086566de31c883b116f8f |
| |
| IA-64: |
| mod_auth_pgsql-2.0.1-7.1.ia64.rpm |
90ca4b0d4160b78edda12d3d300bc2bb |
| |
| x86_64: |
| mod_auth_pgsql-2.0.1-7.1.x86_64.rpm |
542f993464e75b8e6370c453e1dc8c7d |
| |
| Red Hat Enterprise Linux WS (v. 3) |
|
| SRPMS: |
| mod_auth_pgsql-2.0.1-4.ent.1.src.rpm |
78d123ce4dd88d2b473f3def9d1f78d8 |
| |
| IA-32: |
| mod_auth_pgsql-2.0.1-4.ent.1.i386.rpm |
416d662759b7e9a6cac6db24813cadf9 |
| |
| IA-64: |
| mod_auth_pgsql-2.0.1-4.ent.1.ia64.rpm |
4a72fdbf3b94d7d1891e66d8465a5798 |
| |
| x86_64: |
| mod_auth_pgsql-2.0.1-4.ent.1.x86_64.rpm |
cb2bd4600e4fab1ffc7e2b1fbb2a6dfb |
| |
| Red Hat Enterprise Linux WS (v. 4) |
|
| SRPMS: |
| mod_auth_pgsql-2.0.1-7.1.src.rpm |
2a46d8268d1d434ed8ec089bf83e62bd |
| |
| IA-32: |
| mod_auth_pgsql-2.0.1-7.1.i386.rpm |
19b586cf092086566de31c883b116f8f |
| |
| IA-64: |
| mod_auth_pgsql-2.0.1-7.1.ia64.rpm |
90ca4b0d4160b78edda12d3d300bc2bb |
| |
| x86_64: |
| mod_auth_pgsql-2.0.1-7.1.x86_64.rpm |
542f993464e75b8e6370c453e1dc8c7d |
| |
(The unlinked packages above are only available from the Red Hat Network)
|
177042 - CVE-2005-3656 mod_auth_pgsql format string issue