Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:2264-1

Опубликовано: 18 авг. 2020
Источник: suse-cvrf

Описание

Security update for postgresql10

This update for postgresql10 fixes the following issues:

Список пакетов

SUSE Linux Enterprise High Performance Computing 15-ESPOS
libecpg6-10.14-4.25.1
libpq5-10.14-4.25.1
libpq5-32bit-10.14-4.25.1
postgresql10-10.14-4.25.1
postgresql10-contrib-10.14-4.25.1
postgresql10-devel-10.14-4.25.1
postgresql10-docs-10.14-4.25.1
postgresql10-plperl-10.14-4.25.1
postgresql10-plpython-10.14-4.25.1
postgresql10-pltcl-10.14-4.25.1
postgresql10-server-10.14-4.25.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
libecpg6-10.14-4.25.1
libpq5-10.14-4.25.1
libpq5-32bit-10.14-4.25.1
postgresql10-10.14-4.25.1
postgresql10-contrib-10.14-4.25.1
postgresql10-devel-10.14-4.25.1
postgresql10-docs-10.14-4.25.1
postgresql10-plperl-10.14-4.25.1
postgresql10-plpython-10.14-4.25.1
postgresql10-pltcl-10.14-4.25.1
postgresql10-server-10.14-4.25.1
SUSE Linux Enterprise Server 15-LTSS
libecpg6-10.14-4.25.1
libpq5-10.14-4.25.1
libpq5-32bit-10.14-4.25.1
postgresql10-10.14-4.25.1
postgresql10-contrib-10.14-4.25.1
postgresql10-devel-10.14-4.25.1
postgresql10-docs-10.14-4.25.1
postgresql10-plperl-10.14-4.25.1
postgresql10-plpython-10.14-4.25.1
postgresql10-pltcl-10.14-4.25.1
postgresql10-server-10.14-4.25.1
SUSE Linux Enterprise Server for SAP Applications 15
libecpg6-10.14-4.25.1
libpq5-10.14-4.25.1
libpq5-32bit-10.14-4.25.1
postgresql10-10.14-4.25.1
postgresql10-contrib-10.14-4.25.1
postgresql10-devel-10.14-4.25.1
postgresql10-docs-10.14-4.25.1
postgresql10-plperl-10.14-4.25.1
postgresql10-plpython-10.14-4.25.1
postgresql10-pltcl-10.14-4.25.1
postgresql10-server-10.14-4.25.1

Описание

It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:libecpg6-10.14-4.25.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:libpq5-10.14-4.25.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:libpq5-32bit-10.14-4.25.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:postgresql10-10.14-4.25.1

Ссылки

Описание

It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:libecpg6-10.14-4.25.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:libpq5-10.14-4.25.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:libpq5-32bit-10.14-4.25.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:postgresql10-10.14-4.25.1

Ссылки
Уязвимость SUSE-SU-2020:2264-1