Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE: 2018:3377-1 Important: Fixes for Postgresql96 Security Issues

suse
Calendar Grey October 24, 2018
Dist Suse Esm H88
Crucial enhancements for PostgreSQL 9.6 address security flaws encompassing authentication validations and SQL injection issues.
An update that fixes two vulnerabilities is now available

Summary

This update for postgresql96 to 9.6.10 fixes the following issues: These security issues were fixed: - CVE-2018-10915: libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could have bypassed client-side connection security features, obtain access to higher privileged connections or potentially cause other impact SQL injection, by causing the PQescape() functions to malfunction (bsc#1104199) - CVE-2018-10925: Add missing authorization check on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "CREATE TABLE" privileges could have exploited this to read arbitrary bytes server memory. If the attacker also had certain "INSERT" and

References

#1104199 #1104202

Cross- CVE-2018-10915 CVE-2018-10925

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Linux Enterprise Server 12-LTSS

SUSE Linux Enterprise Desktop 12-SP3

SUSE Enterprise Storage 4

https://www.suse.com/security/cve/CVE-2018-10915.html

https://www.suse.com/security/cve/CVE-2018-10925.html

https://bugzilla.suse.com/1104199

https://bugzilla.suse.com/1104202

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:3377-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here