Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2023:0113

Опубликовано: 12 янв. 2023
Источник: rocky
Оценка: Moderate

Описание

Moderate: postgresql:10 security update

PostgreSQL is an advanced object-relational database management system (DBMS).

Security Fix(es):

  • postgresql: Extension scripts replace objects not belonging to the extension. (CVE-2022-2625)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
postgresqlx86_641.module+el8.7.0+1118+c6c6f44apostgresql-10.23-1.module+el8.7.0+1118+c6c6f44a.x86_64.rpm
postgresql-contribx86_641.module+el8.7.0+1118+c6c6f44apostgresql-contrib-10.23-1.module+el8.7.0+1118+c6c6f44a.x86_64.rpm
postgresql-docsx86_641.module+el8.7.0+1118+c6c6f44apostgresql-docs-10.23-1.module+el8.7.0+1118+c6c6f44a.x86_64.rpm
postgresql-plperlx86_641.module+el8.7.0+1118+c6c6f44apostgresql-plperl-10.23-1.module+el8.7.0+1118+c6c6f44a.x86_64.rpm
postgresql-plpython3x86_641.module+el8.7.0+1118+c6c6f44apostgresql-plpython3-10.23-1.module+el8.7.0+1118+c6c6f44a.x86_64.rpm
postgresql-pltclx86_641.module+el8.7.0+1118+c6c6f44apostgresql-pltcl-10.23-1.module+el8.7.0+1118+c6c6f44a.x86_64.rpm
postgresql-serverx86_641.module+el8.7.0+1118+c6c6f44apostgresql-server-10.23-1.module+el8.7.0+1118+c6c6f44a.x86_64.rpm
postgresql-server-develx86_641.module+el8.7.0+1118+c6c6f44apostgresql-server-devel-10.23-1.module+el8.7.0+1118+c6c6f44a.x86_64.rpm
postgresql-staticx86_641.module+el8.7.0+1118+c6c6f44apostgresql-static-10.23-1.module+el8.7.0+1118+c6c6f44a.x86_64.rpm
postgresql-testx86_641.module+el8.7.0+1118+c6c6f44apostgresql-test-10.23-1.module+el8.7.0+1118+c6c6f44a.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8
ubuntu
почти 3 года назад

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.

CVSS3: 7.1
redhat
почти 3 года назад

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.

CVSS3: 8
nvd
почти 3 года назад

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.

CVSS3: 8
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 8
debian
почти 3 года назад

A vulnerability was found in PostgreSQL. This attack requires permissi ...