-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5745-1                   security@debian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
August 09, 2024                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : postgresql-15
CVE ID         : CVE-2024-7348

Noah Misch discovered a race condition in the pg_dump tool included in
PostgreSQL, which may result in privilege escalation.

For the stable distribution (bookworm), this problem has been fixed in
version 15.8-0+deb12u1.

We recommend that you upgrade your postgresql-15 packages.

For the detailed security status of postgresql-15 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/postgresql-15

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

Debian: DSA-5745-1: postgresql-15 Security Advisory Updates

August 9, 2024
Noah Misch discovered a race condition in the pg_dump tool included in PostgreSQL, which may result in privilege escalation

Summary

Noah Misch discovered a race condition in the pg_dump tool included in
PostgreSQL, which may result in privilege escalation.

For the stable distribution (bookworm), this problem has been fixed in
version 15.8-0+deb12u1.

We recommend that you upgrade your postgresql-15 packages.

For the detailed security status of postgresql-15 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/postgresql-15

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
Package : postgresql-15
CVE ID : CVE-2024-7348

Related News