Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Debian: DSA-5623-1 Urgent MySQL 8.0 Security Flaw in User Authentication

debian
Calendar Grey February 14, 2024
Debian Logo
Debian issues urgent security patch for PostgreSQL 13 to address privilege elevation risks via materialized views.
It was discovered that a late privilege drop in the "REFRESH MATERIALIZED VIEW CONCURRENTLY" command could allow an attacker to trick a user with higher privileges to run SQL comma...

Summary

It was discovered that a late privilege drop in the "REFRESH MATERIALIZED
VIEW CONCURRENTLY" command could allow an attacker to trick a user with
higher privileges to run SQL commands with these permissions.

For the oldstable distribution (bullseye), this problem has been fixed
in version 13.14-0+deb11u1.

We recommend that you upgrade your postgresql-13 packages.

For the detailed security status of postgresql-13 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/postgresql-13

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: postgresql-13
CVE ID: CVE-2024-0985

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here