We have relaunched: What's new at ZDNet Asia?

PostgreSQL issues 'critical' security fix

Summary

Developers urge users of open-source database to update their installations immediately to protect themselves.

Events

The 2nd InfoSecurity Summit HK 2010
17 Mar 2010

Hong Kong Convention and Exhibition Centre, Hong Kong

IT Architect Regional Conference Singapore 2010
20 - 21 Apr 2010

Singapore Management University, Singapore

The Internet Show 2010
21-22 Apr 2010

Suntec Singapore

The developers of the open-source PostgreSQL database have issued a "critical" update, urging users of the software to modify their installations immediately to protect themselves from possible exploits.

The fix--which can be downloaded from PostgreSQL's Web site--applies to the most recent version 8.1 of PostgreSQL, which was released just last November, in addition to older versions 8, 7.4 and 7.3.

"The fixes in the 8.1 and 8.0 branches are critical, especially for Windows users, and users of these branches are urged to update at their earliest opportunity," PostgreSQL project member Marc Fournier wrote in an e-mail. A message was also posted online.

Fournier said one fix repaired a denial-of-service vulnerability that could affect PostgreSQL running on Windows systems if too many connection attempts were simultaneously made to the database.

"Another critical fix repairs an error in ReadBuffer that can cause data loss due to overwriting recently added pages," he wrote. "This applies to the 8.1 and 8.0 branches on all platforms."

The project member added that further details of the problems will appear in the documentation for the updated versions of the software. It will take a few days for these details to be available online, he said.

PostgreSQL is an open-source project constructed by about 200 software developers and is licensed under the BSD license, which allows it to be used in free or commercial software products at no charge.

It is one of the most popular open-source databases. The previous version, 8.0, saw an estimated 1 million downloads within seven months of release, according to the project's Web site. The database also comes free with a number of Linux distributions.

Back in November of last year, Sun Microsystems announced plans to distribute and support PostgreSQL.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment
Transform your business interactions with real-time voice, video and telepresence solutions.
Tech Vendor: Cisco

ZDNet Asia Live

SEO Jobs in India - ZDNet Asia http://bit.ly/c2JxOH

11 hours 57 minutes ago by jagbirsinghseo on topsy

[TECH] URL Shorteners slow Web redirection. - http://bit.ly/bySnWK @zdnetasia

URL shorteners are great but they can slow web redirection & you pray it would never go down http://bit.ly/bySnWK via @zdnetasia

#Cloud #Telecom Indian IT to clock double-digit growth in 2010 - Zd Net Asia.com: ... manager of India and Sou... http://bit.ly/dilbUI #TCN

15 hours 29 minutes ago by telecomcloudnet on topsy

Temasek Holdings eyeing tech stocks, indicating optimistic outlook on IT sector. http://bit.ly/aM7VwU

URL shorteners slow Web redirection. http://bit.ly/bySnWK

Chinese agencies cry foul over Google. http://bit.ly/by6rwV

Philippine antipiracy drive focuses on enterprises. http://bit.ly/aWryDC

Gartner: China to become world's fastest-growing enterprise software market. http://bit.ly/bqJTtb

all of sg's isps have been practising compulsory invisible proxy for all home subscribers at their backend since many years back alre...

18 hours 55 minutes ago by melvinchia on Web filters mean bad news for business

it is not to good for china.
Proactol

21 hours 40 minutes ago by nathonastle on Chinese ad partners beg Google for information

Salesforce.com is giving 5,000 developers access to its social networking and collaboration platform http://bit.ly/9dbNw5

21 hours 48 minutes ago by abhishekkatiyar on topsy

RT @zdnetasia: HP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6

For those with a computer science background, or interested in the high performance computing scene: http://bit.ly/9vFC3i

HP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6

** S'pore govt launches traffic Web app. http://www.zdnetasia.com/s-pore-...

the new look site is very nice @zdnetasia @zdnetaustralia

Big up to my peeps at www.ZDNet.com.au (and www.ZDNetasia.com and www.ZDNet.com.uk). Loving the redesign!

Holiday homes for sale : ZDNet Asia Blogs : by http://bit.ly/aNsfp1

1 day 44 minutes ago by moonflowerstarf on topsy

McAfee steps up cloud assurance - Zd Net Asia.com
http://www.zdnetasia.com/mcafee-...

Interesting take on social analystics. http://www.zdnetasia.com/blogs/w...

Very good explanation of JMX

1 day 45 minutes ago by Babith B on Managing applications with JMX

The reaction to a report issued Tuesday by Flurry Analytics managed to completely overlook some interesting news--the Android-based Motorola Droid outsold the original iPhone over the same period of time following their respective launches--to focus instead on the sales numbers for the Nexus One.

1 day 49 minutes ago by lonemavericks on diggs

Another ZTE story....

2 days 51 minutes ago by Moderate Your Greed on Philippines opens bid for final 3G license

We at www.fifosys.com have also seen a growth in IT outsourcing and anticipate it as a growing field.

2 days 24 minutes ago by sarah Jane on Companies' outsourcing spend to increase

I agree with you. The iSiVaL is super portable and TVs can't expand their image size. I recorded a video that might bring some ideas to...

2 days 55 minutes ago by Jesse B Andersen on Buying a projector? Try an LED TV instead

hermm... he deserved it.. he shud not talk abt sensitive things like tat, well, he shud think twice before saying all those things, event...

2 days 33 minutes ago by ... on Facebook user charged in Malaysia

Password manager tools are potential security threat. Criminals who hack into the computer can use the password manager to log onto any s...

2 days 33 minutes ago by ohanae on What defaults should random password generators use?

I've found the cross platform utility unetbootin to be rather handy for this kind of thing as well.

2 days 7 minutes ago by Jim on Use Live USB Creator to install Fedora 12 from a USB stick

Thanks for the article. I think the debug command has an "\" after "C:" it should say w32tm /debug /enable /file:C:\l...

2 days 7 minutes ago by Roger Biefer on Manage time accuracy with W32Tm

available in singapore now
http://www.portablemall.com.sg/goods-71-Microsoft+Zune+HD+32GB+-+Platinum.html

2 days 44 minutes ago by steve on Microsoft coy on apps for Zune HD

How about just using http://www.random.org/strings/? It is very configurable, satisfies all of the flexibility requirements you have ment...

2 days 50 minutes ago by Varun V Nair on What defaults should random password generators use?

Wi-Fi as the "Rodney Dangerfield of wireless", is a catchy metaphor, but it's already been used. In fact, it was the title of a...

3 days 49 minutes ago by Martin Suter on Selina Lo: Wired up for Wi-Fi in Asia

Dear Sir/Madam, I am Narasimha Rao.L. From bangalore India , i searching job in abroad , in electronics field, i have 6+ years exp....

4 days 51 minutes ago by Anonymous on Hot tech jobs in Singapore

Good article, computational aspect of acquired knowledge from the social platform is really questionable, given that there are a lot of p...

4 days 57 minutes ago by JN on What will social analytics say about your company?