Описание
ELSA-2025-1742: postgresql security update (IMPORTANT)
[13.18-1]
- Update to 13.18
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
postgresql-docs
13.20-1.el9_5
postgresql-private-devel
13.20-1.el9_5
postgresql-server-devel
13.20-1.el9_5
postgresql-static
13.20-1.el9_5
postgresql-test
13.20-1.el9_5
postgresql-test-rpm-macros
13.20-1.el9_5
postgresql-upgrade-devel
13.20-1.el9_5
postgresql
13.20-1.el9_5
postgresql-contrib
13.20-1.el9_5
postgresql-plperl
13.20-1.el9_5
postgresql-plpython3
13.20-1.el9_5
postgresql-pltcl
13.20-1.el9_5
postgresql-private-libs
13.20-1.el9_5
postgresql-server
13.20-1.el9_5
postgresql-upgrade
13.20-1.el9_5
Oracle Linux x86_64
postgresql
13.20-1.el9_5
postgresql-contrib
13.20-1.el9_5
postgresql-plperl
13.20-1.el9_5
postgresql-plpython3
13.20-1.el9_5
postgresql-pltcl
13.20-1.el9_5
postgresql-private-libs
13.20-1.el9_5
postgresql-server
13.20-1.el9_5
postgresql-upgrade
13.20-1.el9_5
postgresql-docs
13.20-1.el9_5
postgresql-private-devel
13.20-1.el9_5
postgresql-server-devel
13.20-1.el9_5
postgresql-static
13.20-1.el9_5
postgresql-test
13.20-1.el9_5
postgresql-test-rpm-macros
13.20-1.el9_5
postgresql-upgrade-devel
13.20-1.el9_5
Связанные CVE
Связанные уязвимости
Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.
Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.
Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.
Improper neutralization of quoting syntax in PostgreSQL libpq function ...