{"id":114,"date":"2011-09-26T23:58:42","date_gmt":"2011-09-26T23:58:42","guid":{"rendered":"http:\/\/blogs.gentoo.org\/titanofold\/?p=114"},"modified":"2011-09-26T23:58:42","modified_gmt":"2011-09-26T23:58:42","slug":"security-bugs-and-perl-fix-postgresql","status":"publish","type":"post","link":"https:\/\/blogs.gentoo.org\/titanofold\/2011\/09\/26\/security-bugs-and-perl-fix-postgresql\/","title":{"rendered":"Security, Bugs and Perl Fix &#8211; PostgreSQL"},"content":{"rendered":"<p>PostgreSQL released an update for all supported branches today, which includes a minor\/major security fix and a minor\/major enhancement, and you can and should get them now.<!--more--><\/p>\n<p>The <a title=\"&lt;dev-db\/postgresql-server-{8.2.22,8.3.16,8.4.9,9.0.5,9.1.1} Blowfish Signed-Character Bug (CVE-2011-2483)\" href=\"https:\/\/bugs.gentoo.org\/show_bug.cgi?id=384539\">arches are busy<\/a> (bugs.gentoo.org) testing the packages, and will stabilize them as quick as they can. <em>But<\/em>, if you&#8217;re using the Blowfish cipher from pg_crypto, you probably won&#8217;t want to wait that long.<\/p>\n<p>A <a title=\"crypt_blowfish 1.1; Owl glibc security update on owl-announce mailing list\" href=\"http:\/\/www.openwall.com\/lists\/announce\/2011\/06\/21\/1\">bug was found<\/a> (www.openwall.com) that encryption code could give wrong results on platforms where char is signed (which is most), leading to encrypted passwords being weaker than they should be.<\/p>\n<p>If you are running a PostgreSQL <strong>server<\/strong> using the <strong>Blowfish<\/strong> cipher from <strong>pg_crypto<\/strong>, <strong><em>update now<\/em><\/strong>. If you&#8217;re not using pg_crypto in any of your databases, you&#8217;re safe and can wait for the latest versions to be stabilized, though I&#8217;d still recommend to make the move. If you don&#8217;t even have a PostgreSQL server on your machine, you&#8217;re doubly safe.<\/p>\n<p>So, the security fix is minor if you don&#8217;t use the cipher, but major if you do.<\/p>\n<p>On to Perl, 5.14 support was finally patched in. If you&#8217;ve been waiting for PostgreSQL to get this support going, this is a major enhancment, otherwise it&#8217;ll be a dull and dreary minor enhancement. Again, this only affects server owners.<\/p>\n<p>There have been many other fixes, too. Check the <a title=\"PostgreSQL 2011-09-26 Cumulative Bug-Fix Release\" href=\"http:\/\/www.postgresql.org\/about\/news.1355\">news announcement<\/a> (www.postgresql.org) for more information.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>PostgreSQL released an update for all supported branches today, which includes a minor\/major security fix and a minor\/major enhancement, and you can and should get them now.<\/p>\n","protected":false},"author":136,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true},"categories":[3,5,4],"tags":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p1tO5a-1Q","_links":{"self":[{"href":"https:\/\/blogs.gentoo.org\/titanofold\/wp-json\/wp\/v2\/posts\/114"}],"collection":[{"href":"https:\/\/blogs.gentoo.org\/titanofold\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.gentoo.org\/titanofold\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.gentoo.org\/titanofold\/wp-json\/wp\/v2\/users\/136"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.gentoo.org\/titanofold\/wp-json\/wp\/v2\/comments?post=114"}],"version-history":[{"count":8,"href":"https:\/\/blogs.gentoo.org\/titanofold\/wp-json\/wp\/v2\/posts\/114\/revisions"}],"predecessor-version":[{"id":122,"href":"https:\/\/blogs.gentoo.org\/titanofold\/wp-json\/wp\/v2\/posts\/114\/revisions\/122"}],"wp:attachment":[{"href":"https:\/\/blogs.gentoo.org\/titanofold\/wp-json\/wp\/v2\/media?parent=114"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.gentoo.org\/titanofold\/wp-json\/wp\/v2\/categories?post=114"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.gentoo.org\/titanofold\/wp-json\/wp\/v2\/tags?post=114"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}