Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Mageia: MGASA-2021-0221 Critical: PostgreSQL Memory Flaws

mageia
Calendar Grey May 23, 2021
Dist Mageia Esm H88
Recent updates to PostgreSQL packages as indicated by Mageia's security advisory have successfully resolved issues related to buffer overflow and memory leak vulnerabilities.
Buffer overrun from integer overflow in array subscripting calculations (CVE-2021-32027)

Summary

Buffer overrun from integer overflow in array subscripting calculations (CVE-2021-32027).
Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE. (CVE-2021-32028).
Memory disclosure in partitioned-table UPDATE ... RETURNING. (CVE-2021-32029).

References

- https://bugs.mageia.org/show_bug.cgi?id=28929

- https://www.postgresql.org/about/news/postgresql-133-127-1112-1017-and-9622-released-2210/

- https://www.cve.org/CVERecord?id=CVE-2021-32027

- https://www.cve.org/CVERecord?id=CVE-2021-32029

- https://www.cve.org/CVERecord?id=CVE-2021-32029

Resolution

SRPMS

- 8/core/postgresql11-11.12-1.mga8

- 8/core/postgresql13-13.3-1.mga8

- 7/core/postgresql9.6-9.6.22-1.mga7

- 7/core/postgresql11-11.12-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 23 May 2021
URL: https://advisories.mageia.org/MGASA-2021-0221.html
Type: security
CVE: CVE-2021-32027, CVE-2021-32029, CVE-2021-32029

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here