Insecure generation of random numbers In postgresql84
Description
PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random numbers, which might allow remote authenticated users to have an unspecified impact via vectors related to the "contrib/pgcrypto functions."
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel5 | 0:8.4.18-1.el5_10 | ||
rpm rhel5 | - | - | |
rpm rhel6 | 0:8.4.18-1.el6_4 |
Aliases
1. 2. 3.