It was found that the chkpass extension did not check the result of a call to crypt(). An authenticated database user could possibly trigger this flaw and cause PostgreSQL to crash. Acknowledgements: Red Hat would like to thank the PostgreSQL project for reporting this issue. Upstream acknowledges Honza Horak and Bruce Momjian as the original reporters.
This is now public, although unfortunately it looks like it has two CVEs fixed in one patch (CVE-2014-0065 for buffer overruns, CVE-2014-0066 for crypt()) https://github.com/postgres/postgres/commit/01824385aead50e557ca1af28640460fa9877d51
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 5 Via RHSA-2014:0211 https://rhn.redhat.com/errata/RHSA-2014-0211.html
This issue has been addressed in following products: Red Hat Software Collections for RHEL-6 Via RHSA-2014:0221 https://rhn.redhat.com/errata/RHSA-2014-0221.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2014:0249 https://rhn.redhat.com/errata/RHSA-2014-0249.html
This issue has been addressed in following products: CloudForms Management Engine 5.x Via RHSA-2014:0469 https://rhn.redhat.com/errata/RHSA-2014-0469.html