Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

suse-cvrf Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

openSUSE-SU-2021:3758-1

ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 22 нояб. 2021
Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: suse-cvrf

ОписаниС

Security update for postgresql12

This update for postgresql12 fixes the following issues:

  • CVE-2021-23214: Make the server reject extraneous data after an SSL or GSS encryption handshake (bsc#1192516).
  • CVE-2021-23222: Make libpq reject extraneous data after an SSL or GSS encryption handshake (bsc#1192516).

Бписок ΠΏΠ°ΠΊΠ΅Ρ‚ΠΎΠ²

openSUSE Leap 15.3
postgresql12-12.9-8.26.1
postgresql12-contrib-12.9-8.26.1
postgresql12-devel-12.9-8.26.1
postgresql12-docs-12.9-8.26.1
postgresql12-llvmjit-12.9-8.26.1
postgresql12-plperl-12.9-8.26.1
postgresql12-plpython-12.9-8.26.1
postgresql12-pltcl-12.9-8.26.1
postgresql12-server-12.9-8.26.1
postgresql12-server-devel-12.9-8.26.1
postgresql12-test-12.9-8.26.1

ОписаниС

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.


Π—Π°Ρ‚Ρ€ΠΎΠ½ΡƒΡ‚Ρ‹Π΅ ΠΏΡ€ΠΎΠ΄ΡƒΠΊΡ‚Ρ‹
openSUSE Leap 15.3:postgresql12-12.9-8.26.1
openSUSE Leap 15.3:postgresql12-contrib-12.9-8.26.1
openSUSE Leap 15.3:postgresql12-devel-12.9-8.26.1
openSUSE Leap 15.3:postgresql12-docs-12.9-8.26.1

Бсылки

ОписаниС

A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.


Π—Π°Ρ‚Ρ€ΠΎΠ½ΡƒΡ‚Ρ‹Π΅ ΠΏΡ€ΠΎΠ΄ΡƒΠΊΡ‚Ρ‹
openSUSE Leap 15.3:postgresql12-12.9-8.26.1
openSUSE Leap 15.3:postgresql12-contrib-12.9-8.26.1
openSUSE Leap 15.3:postgresql12-devel-12.9-8.26.1
openSUSE Leap 15.3:postgresql12-docs-12.9-8.26.1

Бсылки
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ openSUSE-SU-2021:3758-1