The PostgreSQL Global Development Group today released security updates for all
active branches of the PostgreSQL database system, including versions 9.1.4,
9.0.8, 8.4.12 and 8.3.19.
Users of the crypt(text, text) function with DES encryption in the optional
pg_crypto module should upgrade their installations immediately, if you have'nt
already updated since the port was patched on May 30. All other database
administrators are urged to upgrade your version of PostgreSQL at the
next scheduled downtime.
Fix incorrect password transformation in contrib/pgcryptoâs DES
This was fixed in a patch release for the FreeBSD ports on May 30.
Ignore SECURITY DEFINER and SET attributes for a procedural
languageâs call handle