Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-3082

Опубликовано: 21 мар. 2025
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2025-3082: postgresql:12 security update (IMPORTANT)

pgaudit postgres-decoderbufs postgresql [12.22-3]

  • Fix backport for CVE-2025-1094

[12.22-2]

  • Backport fix for CVE-2025-1094

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module postgresql:12 is enabled

pg_repack

1.4.6-3.module+el8.9.0+90107+c48bae1a

pgaudit

1.4.0-7.module+el8.10.0+90397+67dad74f

postgres-decoderbufs

0.10.0-2.module+el8.9.0+90107+c48bae1a

postgresql

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-contrib

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-docs

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-plperl

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-plpython3

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-pltcl

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-server

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-server-devel

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-static

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-test

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-test-rpm-macros

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-upgrade

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-upgrade-devel

12.22-3.module+el8.10.0+90540+03ca8735

Oracle Linux x86_64

Module postgresql:12 is enabled

pg_repack

1.4.6-3.module+el8.9.0+90107+c48bae1a

pgaudit

1.4.0-7.module+el8.10.0+90397+67dad74f

postgres-decoderbufs

0.10.0-2.module+el8.9.0+90107+c48bae1a

postgresql

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-contrib

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-docs

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-plperl

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-plpython3

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-pltcl

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-server

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-server-devel

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-static

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-test

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-test-rpm-macros

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-upgrade

12.22-3.module+el8.10.0+90540+03ca8735

postgresql-upgrade-devel

12.22-3.module+el8.10.0+90540+03ca8735

Связанные CVE

Связанные уязвимости

CVSS3: 8.1
ubuntu
4 месяца назад

Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.

CVSS3: 8.1
redhat
4 месяца назад

Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.

CVSS3: 8.1
nvd
4 месяца назад

Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.

CVSS3: 8.1
msrc
4 месяца назад

Описание отсутствует

CVSS3: 8.1
debian
4 месяца назад

Improper neutralization of quoting syntax in PostgreSQL libpq function ...