Bug 966436 (CVE-2016-0773) - VUL-0: CVE-2016-0773: postgresql: buffer overrun in regular expression processing
Summary: VUL-0: CVE-2016-0773: postgresql: buffer overrun in regular expression proces...
Status: RESOLVED FIXED
: 978323 (view as bug list)
Alias: CVE-2016-0773
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/161835/
Whiteboard: CVSSv2:RedHat:CVE-2016-0773:6.8:(AV:N...
Keywords:
Depends on:
Blocks: 978323
  Show dependency treegraph
 
Reported: 2016-02-12 09:33 UTC by Alexander Bergmann
Modified: 2018-11-07 16:28 UTC (History)
8 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2016-02-12 09:33:49 UTC
http://www.postgresql.org/about/news/1644/
http://www.postgresql.org/docs/current/static/release-9-5-1.html

Release Notes 9.5.1:

Fix infinite loops and buffer-overrun problems in regular expressions (Tom Lane)

Very large character ranges in bracket expressions could cause infinite loops in some cases, and memory overwrites in other cases. (CVE-2016-0773)


References:
https://bugzilla.redhat.com/show_bug.cgi?id=1303832
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-0773
http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-0773.html
Comment 2 Swamp Workflow Management 2016-02-12 23:00:30 UTC
bugbot adjusting priority
Comment 5 Reinhard Max 2016-02-15 11:25:50 UTC
1. What is SLE10 TD?
2. Several of the issues mentioned in SMASH have already been fixed with the previous update.
3. Please also include the pending request for postgresql-init (94822) in this update.
Comment 7 Jeff Christensen 2016-02-18 14:54:52 UTC
I have a customer who has asked if this will be addressed for sles11 sp3 and sp4. Do you know if it will and if you have an eta?  Thanks so much.
Comment 8 Reinhard Max 2016-02-18 15:47:35 UTC
The SLE-11-SP1 package will also show up on SP3 and SP4. As for the eta, the packaging part is done, but I don't know how long it will take to pass through QA and get released.
Comment 9 Jeff Christensen 2016-02-18 15:51:06 UTC
That sounds great. Thanks very much Reinhard.
Comment 10 Swamp Workflow Management 2016-02-21 10:11:25 UTC
openSUSE-SU-2016:0531-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 966435,966436
CVE References: CVE-2007-4772,CVE-2016-0766,CVE-2016-0773
Sources used:
openSUSE Leap 42.1 (src):    postgresql-init-9.4-6.1, postgresql93-9.3.11-3.2, postgresql93-libs-9.3.11-3.2
openSUSE 13.2 (src):    postgresql93-9.3.11-2.10.1, postgresql93-libs-9.3.11-2.10.1
Comment 11 Swamp Workflow Management 2016-02-22 13:11:40 UTC
SUSE-SU-2016:0539-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 966435,966436
CVE References: CVE-2007-4772,CVE-2016-0766,CVE-2016-0773
Sources used:
SUSE Linux Enterprise Software Development Kit 12 (src):    postgresql93-libs-9.3.11-14.1
SUSE Linux Enterprise Server 12 (src):    postgresql93-9.3.11-14.2
SUSE Linux Enterprise Desktop 12 (src):    postgresql93-9.3.11-14.2
Comment 13 Swamp Workflow Management 2016-02-24 12:13:22 UTC
SUSE-SU-2016:0555-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 578053,966435,966436
CVE References: CVE-2007-4772,CVE-2016-0766,CVE-2016-0773
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    postgresql94-libs-9.4.6-7.1
SUSE Linux Enterprise Software Development Kit 12 (src):    postgresql94-libs-9.4.6-7.1
SUSE Linux Enterprise Server 12-SP1 (src):    postgresql94-9.4.6-7.2, postgresql94-libs-9.4.6-7.1
SUSE Linux Enterprise Server 12 (src):    postgresql94-9.4.6-7.2, postgresql94-libs-9.4.6-7.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    postgresql94-9.4.6-7.2, postgresql94-libs-9.4.6-7.1
SUSE Linux Enterprise Desktop 12 (src):    postgresql94-9.4.6-7.2, postgresql94-libs-9.4.6-7.1
Comment 14 Swamp Workflow Management 2016-02-25 13:12:24 UTC
openSUSE-SU-2016:0578-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 578053,966435,966436
CVE References: CVE-2007-4772,CVE-2016-0766,CVE-2016-0773
Sources used:
openSUSE Leap 42.1 (src):    postgresql94-9.4.6-4.1, postgresql94-libs-9.4.6-4.1
Comment 15 Bernhard Wiedemann 2016-03-07 15:00:20 UTC
This is an autogenerated message for OBS integration:
This bug (966436) was mentioned in
https://build.opensuse.org/request/show/367653 Factory / postgresql93
Comment 16 Swamp Workflow Management 2016-03-07 17:13:26 UTC
SUSE-SU-2016:0677-1: An update that fixes 5 vulnerabilities is now available.

Category: security (important)
Bug References: 949669,949670,966435,966436
CVE References: CVE-2007-4772,CVE-2015-5288,CVE-2015-5289,CVE-2016-0766,CVE-2016-0773
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    postgresql94-libs-9.4.6-0.14.3
SUSE Linux Enterprise Server 11-SP4 (src):    postgresql94-9.4.6-0.14.3, postgresql94-libs-9.4.6-0.14.3
SUSE Linux Enterprise Desktop 11-SP4 (src):    postgresql94-9.4.6-0.14.3, postgresql94-libs-9.4.6-0.14.3
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    postgresql94-9.4.6-0.14.3, postgresql94-libs-9.4.6-0.14.3
Comment 17 Bernhard Wiedemann 2016-03-08 10:00:17 UTC
This is an autogenerated message for OBS integration:
This bug (966436) was mentioned in
https://build.opensuse.org/request/show/368148 Factory / postgresql94
Comment 18 Haral Tsitsivas 2016-03-15 22:10:50 UTC
I don't see an update for SLES11SP3 here:
https://www.suse.com/security/cve/CVE-2016-0773.html

Is there one in progress?
Comment 19 Reinhard Max 2016-03-16 07:46:52 UTC
SLES11SP3 is covered by the SLE11SP1 update.
Comment 20 Haral Tsitsivas 2016-03-16 15:39:18 UTC
There are no 11SP1 nor 11SP3 links in this page:

https://www.suse.com/security/cve/CVE-2016-0773.html
Comment 21 Reinhard Max 2016-03-16 16:30:54 UTC
Indeed, I misread 12-SP1 as 11-SP1. Sorry for that.

But anyway, as far as SLE11 goes, I submited the sources for PostgreSQL 9.4.6 only to SP1 and all later SPs of the respective releases should "inherit" the packages from there.

Marcus, can you explain why this only got released for SLE11-SP4 and no older SPs?
Comment 22 Marcus Meissner 2016-03-16 17:02:41 UTC
SLES 11 SP3 has left regular maintenance and support on January 31st 2016.

It has entered the 3 year LTSS phase on 2nd February.

This update happened after that time, so it is no longer released to the general support and maintenance trees of SLES 11 SP3.

We currently have no LTSS update planned, as the severity so far does not meet the LTSS release criteria.

A PTF can be requested by LTSS customers via the regular support channels.

-> issue seems done
Comment 27 Josef Cejka 2016-05-18 07:03:01 UTC
*** Bug 978323 has been marked as a duplicate of this bug. ***