Bug#1030048: pgpool2: CVE-2023-22332

2023-03-01 Thread Christoph Berg
Re: Adrian Bunk > > CVE-2023-22332[0]: > Christoph, is there a reason why this cannot be fixed with a backport > or an upgrade to 4.3.5? Just time (and the RFH on the package that has been open since 2014 and no activity since 2016). I've just uploaded 4.3.5 to unstable. Thanks for the poke, Ch

Bug#1030048: pgpool2: CVE-2023-22332

2023-02-28 Thread Adrian Bunk
On Mon, Jan 30, 2023 at 06:47:23PM +0100, Moritz Mühlenhoff wrote: > Source: pgpool2 > X-Debbugs-CC: t...@security.debian.org > Severity: grave > Tags: security > > Hi, > > The following vulnerability was published for pgpool2. > > CVE-2023-22332[0]: > | Information disclosure vulnerability exis

Bug#1030048: pgpool2: CVE-2023-22332

2023-01-30 Thread Moritz Mühlenhoff
Source: pgpool2 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for pgpool2. CVE-2023-22332[0]: | Information disclosure vulnerability exists in Pgpool-II 4.4.0 to | 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0 to 4.2.