Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Mageia 7 - MGASA-2020-0432 Moderate: PostgreSQL Security Update

mageia
Calendar Grey November 21, 2020
Dist Mageia Esm H88
Recent upgrades to PostgreSQL versions patch vital security vulnerabilities, significantly bolstering system stability and data privacy. Take immediate action!
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24

Summary

A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic connection parameters while dropping security-relevant parameters, an opportunity for a man-in-the-middle attack, or the ability to observe clear-text transmissions, could exist. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. (CVE-2020-25694)
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. (CVE-2020-25695)
psql's \gset allows overwriting specially treated v...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=27607

- https://www.postgresql.org/about/news/postgresql-131-125-1110-1015-9620-and-9524-released-2111/

- https://www.cve.org/CVERecord?id=CVE-2020-25694

- https://www.cve.org/CVERecord?id=CVE-2020-25695

- https://www.cve.org/CVERecord?id=CVE-2020-25696

Resolution

SRPMS

- 7/core/postgresql9.6-9.6.20-1.mga7

- 7/core/postgresql11-11.10-1.mga7

Publication date: 21 Nov 2020
URL: https://advisories.mageia.org/MGASA-2020-0432.html
Type: security
CVE: CVE-2020-25694, CVE-2020-25695, CVE-2020-25696

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here