Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian DSA-5554-1 Critical: PostgreSQL SQL Injection Threat

debian
Calendar Grey November 13, 2023
Debian Logo
Important security patch for the PostgreSQL database highlighting various weaknesses and stressing the need for package enhancements.
Several vulnerabilities have been discovered in the PostgreSQL database system

Summary

CVE-2023-5868

Jingzhou Fu discovered a memory disclosure flaw in aggregate
function calls.

CVE-2023-5869

Pedro Gallegos reported integer overflow flaws resulting in buffer
overflows in the array modification functions.

CVE-2023-5870

Hemanth Sandrana and Mahendrakar Srinivasarao reported that the
pg_cancel_backend role can signal certain superuser processes,
potentially resulting in denial of service.

CVE-2023-39417

Micah Gate, Valerie Woolard, Tim Carey-Smith, and Christoph Berg
reported that an extension script using @substitutions@ within
quoting may allow to perform an SQL injection for an attacker having
database-level CREATE privileges.

For the oldstable distribution (bullseye), these problems have been
fixed in version 13.13-0+deb11u1.

We recommend that you upgrade your postgresql-13 packages.

For the detailed security status of postgresql-13 please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/source-package/postgre...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: postgresql-13
CVE ID: CVE-2023-5868 CVE-2023-5869 CVE-2023-5870 CVE-2023-39417

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here