Quoting Debian Security Advisory (DSA-1909-1) for postgresql-ocaml: ------------------------------------------------------------------- It was discovered that postgresql-ocaml, OCaml bindings to PostgreSQL's libpq, was missing a function to call PQescapeStringConn(). This is needed, because PQescapeStringConn() honours the charset of the connection and prevents insufficient escaping, when certain multibyte character encodings are used. The added function is called escape_string_conn() and takes the established database connection as a first argument. The old escape_string() was kept for backwards compatibility. References: ----------- http://www.debian.org/security/2009/dsa-1909 Debian patch for Lenny: ----------------------- http://security.debian.org/pool/updates/main/p/postgresql-ocaml/postgresql-ocaml_1.7.0-3+lenny1.diff.gz
This issue affects the versions of ocaml-postgresql package, as shipped with Fedora releases of 10 and 11. Please fix.
Created attachment 365028 [details] Local copy of relevant bits from ocaml-postgresql-CVE-2009-2943-lenny.patch
Upstream have released a new version containing this fix (verified by inspecting the code and reading the upstream ChangeLog). So I'm going to upgrade all our branches to this new upstream version.
Built for dist-f13, F12, F11 and F10. Again I cannot attach the Bodhi updates to this bug for some reason. It says "Fault 411: 'Password Expired'" although my password hasn't expired.
Changed my password today (not sure, if this might be related). Anyway, approved the updates.
(In reply to comment #4) > Again I cannot attach the Bodhi updates to this > bug for some reason. It says > "Fault 411: 'Password Expired'" > although my password hasn't expired. How / where did you get that? Bodhi BZ user password may be expired.
(In reply to comment #6) > (In reply to comment #4) > > Again I cannot attach the Bodhi updates to this > > bug for some reason. It says > > "Fault 411: 'Password Expired'" > > although my password hasn't expired. > > How / where did you get that? Bodhi BZ user password may be expired. See: https://bugzilla.redhat.com/show_bug.cgi?id=529321#c3
ocaml-postgresql-1.12.3-1.fc11.2 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.
ocaml-postgresql-1.12.3-1.fc10.2 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.