Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-7128

Опубликовано: 27 окт. 2022
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2022-7128: postgresql:12 security update (MODERATE)

postgresql [12.12-1]

  • Resolves: #2131177
  • Update to version 12.12

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module postgresql:12 is enabled

pg_repack

1.4.6-3.module+el8.5.0+20333+86306fc7

pgaudit

1.4.0-5.module+el8.5.0+20333+86306fc7

postgres-decoderbufs

0.10.0-2.module+el8.5.0+20333+86306fc7

postgresql

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-contrib

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-docs

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-plperl

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-plpython3

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-pltcl

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-server

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-server-devel

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-static

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-test

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-test-rpm-macros

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-upgrade

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-upgrade-devel

12.12-1.module+el8.6.0+20851+edfb83f8

Oracle Linux x86_64

Module postgresql:12 is enabled

pg_repack

1.4.6-3.module+el8.5.0+20333+86306fc7

pgaudit

1.4.0-5.module+el8.5.0+20333+86306fc7

postgres-decoderbufs

0.10.0-2.module+el8.5.0+20333+86306fc7

postgresql

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-contrib

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-docs

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-plperl

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-plpython3

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-pltcl

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-server

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-server-devel

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-static

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-test

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-test-rpm-macros

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-upgrade

12.12-1.module+el8.6.0+20851+edfb83f8

postgresql-upgrade-devel

12.12-1.module+el8.6.0+20851+edfb83f8

Связанные CVE

Связанные уязвимости

CVSS3: 8
ubuntu
почти 3 года назад

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.

CVSS3: 7.1
redhat
почти 3 года назад

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.

CVSS3: 8
nvd
почти 3 года назад

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.

CVSS3: 8
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 8
debian
почти 3 года назад

A vulnerability was found in PostgreSQL. This attack requires permissi ...