Problem Note 69001: Security update for pgpool-II on SAS® Viya® 3.5
Severity: Medium
Description: The following versions of pgpool-II are used with the underlying technology for the SAS® Infrastructure Data Server on SAS Viya 3.5:
- pgpool-II 4.0.6
- pgpool-II 4.0.17
These versions of pgpool-II have the following known security vulnerabilities:
- allows for non-compliant protocols
- allows for weak ciphers
- allows for null ciphers
Potential Impact:
- Weak ciphers can result in a malicious actor decrypting data that contains sensitive information, potentially leading to a complete compromise of confidentiality and integrity.
Updating pgpool-II from 4.0.6 / 4.0.17 to 4.4.4 addresses all of these security concerns.
Applying this update also removes the NULL-SHA256 and AES-CBC ciphers on ports 5431 and 5432 for releases on 23w44 or later using any version of PgPool or PostgreSQL.
To determine whether you need a new order, see SAS KB0037227, "Determine whether you need a new order for PostgreSQL 15 on SAS® Viya® 3.5 (Linux)."
Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.
Note, for these changes to take effect, you must run the FULL playbook, not an UPDATE-ONLY install.
Operating System and Release Information
SAS System | SAS Viya | Linux for x64 | 3.5 | 3.5 | Viya | Viya |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
Type: | Problem Note |
Priority: | high |
Date Modified: | 2024-03-07 15:13:07 |
Date Created: | 2022-03-13 17:43:50 |