Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2020:5620

Опубликовано: 17 дек. 2020
Источник: rocky
Оценка: Important

Описание

Important: postgresql:12 security update

PostgreSQL is an advanced object-relational database management system (DBMS).

The following packages have been upgraded to a later upstream version: postgresql (12.5).

Security Fix(es):

  • postgresql: Reconnection can downgrade connection security settings (CVE-2020-25694)

  • postgresql: Multiple features escape "security restricted operation" sandbox (CVE-2020-25695)

  • postgresql: Uncontrolled search path element in logical replication (CVE-2020-14349)

  • postgresql: Uncontrolled search path element in CREATE EXTENSION (CVE-2020-14350)

  • postgresql: psql's \gset allows overwriting specially treated variables (CVE-2020-25696)

  • postgresql: ALTER ... DEPENDS ON EXTENSION is missing authorization checks (CVE-2020-1720)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
postgres-decoderbufsx86_642.module+el8.5.0+684+c3892ef9postgres-decoderbufs-0.10.0-2.module+el8.5.0+684+c3892ef9.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
больше 4 лет назад

ELSA-2020-5620-1: postgresql:12 security update (IMPORTANT)

oracle-oval
около 4 лет назад

ELSA-2021-9290: rh-postgresql10-postgresql security update (IMPORTANT)

suse-cvrf
больше 4 лет назад

Security update for postgresql12

suse-cvrf
больше 4 лет назад

Security update for postgresql10

oracle-oval
почти 5 лет назад

ELSA-2020-3669: postgresql:10 security and bug fix update (MODERATE)