Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:3342-1

Опубликовано: 17 авг. 2023
Источник: suse-cvrf

Описание

Security update for postgresql15

This update for postgresql15 fixes the following issues:

  • Update to 15.4
  • CVE-2023-39417: Fixed potential SQL injection for trusted extensions. (bsc#1214059)
  • CVE-2023-39418: Fix MERGE to enforce row security. (bsc#1214061)

Список пакетов

SUSE Linux Enterprise Server 12 SP5
libecpg6-15.4-3.12.1
libecpg6-32bit-15.4-3.12.1
libpq5-15.4-3.12.1
libpq5-32bit-15.4-3.12.1
postgresql15-15.4-3.12.1
postgresql15-contrib-15.4-3.12.1
postgresql15-docs-15.4-3.12.1
postgresql15-plperl-15.4-3.12.1
postgresql15-plpython-15.4-3.12.1
postgresql15-pltcl-15.4-3.12.1
postgresql15-server-15.4-3.12.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
libecpg6-15.4-3.12.1
libecpg6-32bit-15.4-3.12.1
libpq5-15.4-3.12.1
libpq5-32bit-15.4-3.12.1
postgresql15-15.4-3.12.1
postgresql15-contrib-15.4-3.12.1
postgresql15-docs-15.4-3.12.1
postgresql15-plperl-15.4-3.12.1
postgresql15-plpython-15.4-3.12.1
postgresql15-pltcl-15.4-3.12.1
postgresql15-server-15.4-3.12.1
SUSE Linux Enterprise Software Development Kit 12 SP5
postgresql15-devel-15.4-3.12.1
postgresql15-server-devel-15.4-3.12.1

Описание

IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:libecpg6-15.4-3.12.1
SUSE Linux Enterprise Server 12 SP5:libecpg6-32bit-15.4-3.12.1
SUSE Linux Enterprise Server 12 SP5:libpq5-15.4-3.12.1
SUSE Linux Enterprise Server 12 SP5:libpq5-32bit-15.4-3.12.1

Ссылки

Описание

A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:libecpg6-15.4-3.12.1
SUSE Linux Enterprise Server 12 SP5:libecpg6-32bit-15.4-3.12.1
SUSE Linux Enterprise Server 12 SP5:libpq5-15.4-3.12.1
SUSE Linux Enterprise Server 12 SP5:libpq5-32bit-15.4-3.12.1

Ссылки