A flaw was found in the way the PostgreSQL enforced permission checks on scripts written in PL/Tcl. Once the PL/Tcl procedural language was registered on particular database, a remote, authenticated user, privileged to create databases, running a specially-crafted PL/Tcl script, could use this flaw to bypass intended PL/Tcl trusted mode restrictions, allowing them to run arbitrary Tcl scripts with the privileges of the database server. References: [1] PostgreSQL PL/Tcl procedural language manual page: http://www.postgresql.org/docs/8.1/interactive/pltcl.html
This is CVE-2010-1170.
This is now public: http://www.postgresql.org/support/security.html
postgresql-8.4.4-1.fc12 has been submitted as an update for Fedora 12. http://admin.fedoraproject.org/updates/postgresql-8.4.4-1.fc12
postgresql-8.3.11-1.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/postgresql-8.3.11-1.fc11
postgresql-8.4.4-1.fc13 has been submitted as an update for Fedora 13. http://admin.fedoraproject.org/updates/postgresql-8.4.4-1.fc13
postgresql-8.4.4-1.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in this bug report.
postgresql-8.4.4-1.fc12 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report.
postgresql-8.3.11-1.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.
Upstream commit (head/master branch): http://git.postgresql.org/gitweb?p=postgresql.git;a=commitdiff;h=989b6ff11931dd742552dd3b8d51f3225ce9fb2e http://git.postgresql.org/gitweb?p=postgresql.git;a=commitdiff;h=09d3c3f3353c0a836935a87896097bae2d5bd81c It seems upstream had some issues with CVS -> git repo sync, adding link to relevant commit list mail for completeness: http://archives.postgresql.org/pgsql-committers/2010-05/msg00221.php
This issue has been addressed in following products: Red Hat Enterprise Linux 3 Via RHSA-2010:0427 https://rhn.redhat.com/errata/RHSA-2010-0427.html
This issue has been addressed in following products: Red Hat Enterprise Linux 4 Via RHSA-2010:0428 https://rhn.redhat.com/errata/RHSA-2010-0428.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2010:0429 https://rhn.redhat.com/errata/RHSA-2010-0429.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2010:0430 https://rhn.redhat.com/errata/RHSA-2010-0430.html
Created sepostgresql tracking bugs for this issue Affects: fedora-all [bug 636659]