-
- Downloads
pgcrypto: Detect and report too-short crypt() salts.
Certain short salts crashed the backend or disclosed a few bytes of backend memory. For existing salt-induced error conditions, emit a message saying as much. Back-patch to 9.0 (all supported versions). Josh Kupershmidt Security: CVE-2015-5288
Showing
- contrib/pgcrypto/crypt-blowfish.c 17 additions, 2 deletionscontrib/pgcrypto/crypt-blowfish.c
- contrib/pgcrypto/crypt-des.c 19 additions, 3 deletionscontrib/pgcrypto/crypt-des.c
- contrib/pgcrypto/expected/crypt-blowfish.out 9 additions, 0 deletionscontrib/pgcrypto/expected/crypt-blowfish.out
- contrib/pgcrypto/expected/crypt-des.out 4 additions, 0 deletionscontrib/pgcrypto/expected/crypt-des.out
- contrib/pgcrypto/expected/crypt-xdes.out 24 additions, 0 deletionscontrib/pgcrypto/expected/crypt-xdes.out
- contrib/pgcrypto/px-crypt.c 1 addition, 1 deletioncontrib/pgcrypto/px-crypt.c
- contrib/pgcrypto/sql/crypt-blowfish.sql 9 additions, 0 deletionscontrib/pgcrypto/sql/crypt-blowfish.sql
- contrib/pgcrypto/sql/crypt-des.sql 4 additions, 0 deletionscontrib/pgcrypto/sql/crypt-des.sql
- contrib/pgcrypto/sql/crypt-xdes.sql 16 additions, 0 deletionscontrib/pgcrypto/sql/crypt-xdes.sql
Loading
Please register or sign in to comment