Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
89

Fedora 41: OpenIPMI 2025-ae55d50be2 Security Advisory Updates

Update to 2.0.36 Fixes CVE-2024-42934. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-ae55d50be2 2025-03-25 01:22:46.359260+00:00 -------------------------------------------------------------------------------- Name : OpenIPMI Product : Fedora 41 Version : 2.0.36 Release : 1.fc41 URL : https://sourceforge.net/projects/openipmi/ Summary : IPMI (Intelligent Platform Management Interface) library and tools Description : The Open IPMI project aims to develop an open code base to allow access to platform information using Intelligent Platform Management Interface (IPMI). This package contains the tools of the OpenIPMI project. -------------------------------------------------------------------------------- Update Information: Update to 2.0.36 Fixes CVE-2024-42934 -------------------------------------------------------------------------------- ChangeLog: * Thu Aug 22 2024 Fedora Release Monitoring - 2.0.36-1 - Update to 2.0.36 (#2302353) - Resolves CVE-2024-42934 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2308383 - CVE-2024-42934 OpenIPMI: missing check on the authorization type on incoming LAN messages in IPMI simulator [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2308383 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-ae55d50be2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . OpenIPMI update in Fedora 41 addresses critical authorization issues for enhanced security.. update, fixes, cve-2024-42934, --------------------------------------------------------------. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 25, 2025 Critical Fedora
98

Red Hat Data Grid 8.1.1 RHSA-2021:0433-01 Moderate Memory Leak Issue

A security update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Data Grid 8.1.1 security update Advisory ID: RHSA-2021:0433-01 Product: Red Hat JBoss Data Grid Advisory URL: https://access.redhat.com/errata/RHSA-2021:0433 Issue date: 2021-02-08 CVE Names: CVE-2020-25644 CVE-2020-25711 CVE-2020-26217 ==================================================================== 1. Summary: A security update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat Data Grid is a distributed, in-memory data store. This release of Red Hat Data Grid 8.1.1 serves as a replacement for Red Hat Data Grid 8.1.0, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Security Fix(es): * wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL (CVE-2020-25644) * XStream: remote code execution due to insecure XML deserialization when relying on blocklists (CVE-2020-26217) * infinispan: authorization check missing for server management operations (CVE-2020-25711) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Refer to the Data Grid 8.1 Upgrade Guide for instructions onupgrading to this version. The References section of this erratum contains a download link (you must log in to download the update). 4. Bugs fixed (https://bugzilla.redhat.com/): 1885485 - CVE-2020-25644 wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL 1897618 - CVE-2020-25711 infinispan: authorization check missing for server management operations 1898907 - CVE-2020-26217 XStream: remote code execution due to insecure XML deserialization when relying on blocklists 5. References: https://access.redhat.com/security/cve/CVE-2020-25644 https://access.redhat.com/security/cve/CVE-2020-25711 https://access.redhat.com/security/cve/CVE-2020-26217 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=data.grid&downloadType=securityPatches&version=8.1 https://docs.redhat.com/en/documentation/red_hat_data_grid/8.1/html/upgrading_data_grid/index 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYCE08tzjgjWX9erEAQiczA//cBXSGydb50uqm54n7mRr650w/tX/KeGy IFa++dkIoJP5aF+nkK46Z+WqSpO+TnPcq4QgOHT0z2211J8smOk1UwRzarogrR+I WkfzO4+r/2oAYJHF9vB8wlYbnFIqaOqCu3MwO+1a58A2ECOZXAKs4EivEMdcvp1+ 7VbnMU2GsgZUvVMsRPRitTJGkkL14UwYP/MZCHQRfdbrbOopjjSYCUt1hzpFmPIu 4tJCvkArKIHksXdBtbb+Y+PFop05hySRDp8ed1bJPcD8+6Lv8ezVh/i1YMdBFJ7F Nq6T7g3InpueJflvfLooZ6Nlf8T+Ar8Dsv6e+6kmSpUQPxgAZJEeNSZBdvbRwVIE O8YqK4nWxxi5R1YehjuR4ax42D3rv+ZWuL8pmr90uDMcmpCp4uM8SEfmEkbhyeVQ UMYmv9oJW2oayvGlKvCkdFoLcN6kdkLmHIAPqdh8QnyuG6GlAxozsJ+566k4gWgI HYLY62IOBHbsBE9dzCIqBSk3/+GvGmnzdEQd+R6a/xRmQ83In2J6BzGbZkzkOvUj 4rqS74Q2YV+hG4PRtlRO9EDolYOLARMW1qJQrWtbwdgXDt9mjPEPXw9FoHpUYitz c0wPDE5hbdp8uwarYP7SuHXLRrCBedHx0reGQyHzBtrJtfqRPWVKd43jeUkUt22R R/ZChTj5mZQ=m0Gn -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical patch release for Ubuntu Server 20.04.5 resolvessignificant vulnerabilities such as buffer overflow and potential data breach.. Red Hat Data Grid, security update, memory leak issues, remote code execution. . LinuxSecurity.com Team

Calendar%202 Feb 08, 2021 Red Hat
100

SUSE: 2020:0752-1 Moderate: PostgreSQL10 Authorization Check Issue

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for postgresql10 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0752-1 Rating: moderate References: #1163985 Cross-References: CVE-2020-1720 Affected Products: SUSE Linux Enterprise Module for Server Applications 15-SP1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 SUSE Linux Enterprise Module for Basesystem 15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for postgresql10 fixes the following issues: PostgreSQL was updated to version 10.12. Security issue fixed: - CVE-2020-1720: Fixed a missing authorization check in the ALTER ... DEPENDS ON extension (bsc#1163985). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15-SP1: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP1-2020-752=1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2020-752=1 - SUSE Linux Enterprise Module for Basesystem 15-SP1: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2020-752=1 Package List: - SUSE Linux Enterprise Module for Server Applications 15-SP1 (aarch64 ppc64le s390x x86_64): libecpg6-10.12-8.9.1 libecpg6-debuginfo-10.12-8.9.1 postgresql10-contrib-10.12-8.9.1 postgresql10-contrib-debuginfo-10.12-8.9.1 postgresql10-debuginfo-10.12-8.9.1 postgresql10-debugsource-10.12-8.9.1 postgresql10-devel-10.12-8.9.1 postgresql10-devel-debuginfo-10.12-8.9.1 postgresql10-plperl-10.12-8.9.1 postgresql10-plperl-debuginfo-10.12-8.9.1 postgresql10-plpython-10.12-8.9.1 postgresql10-plpython-debuginfo-10.12-8.9.1 postgresql10-pltcl-10.12-8.9.1 postgresql10-pltcl-debuginfo-10.12-8.9.1 postgresql10-server-10.12-8.9.1 postgresql10-server-debuginfo-10.12-8.9.1 - SUSE Linux Enterprise Module for Server Applications 15-SP1 (noarch): postgresql10-docs-10.12-8.9.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (aarch64 ppc64le s390x x86_64): postgresql10-debuginfo-10.12-8.9.1 postgresql10-debugsource-10.12-8.9.1 postgresql10-test-10.12-8.9.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (x86_64): libecpg6-32bit-10.12-8.9.1 libecpg6-32bit-debuginfo-10.12-8.9.1 libpq5-32bit-10.12-8.9.1 libpq5-32bit-debuginfo-10.12-8.9.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64): libpq5-10.12-8.9.1 libpq5-debuginfo-10.12-8.9.1 postgresql10-10.12-8.9.1 postgresql10-debuginfo-10.12-8.9.1 postgresql10-debugsource-10.12-8.9.1 References: https://www.suse.com/security/cve/CVE-2020-1720.html https://bugzilla.suse.com/1163985 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Update for postgresql12 resolves a serious issue with guidance for impacted software.. SUSE Linux, postgresql, security update, authorization issue, server applications. . LinuxSecurity.com Team

Calendar%202 Mar 23, 2020 SuSE
100

SUSE: 2020:0715-1 Low: postgresql10 Missing Authorization Check

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for postgresql10 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0715-1 Rating: low References: #1163985 Cross-References: CVE-2020-1720 Affected Products: SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Linux Enterprise Desktop 12-SP4 SUSE Enterprise Storage 5 HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for postgresql10 fixes the following issues: PostgreSQL was updated to version 10.12. Security issue fixed: - CVE-2020-1720: Fixed a missing authorization check in the ALTER ... DEPENDS ON extension (bsc#1163985). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2020-715=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2020-715=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2020-715=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-715=1 - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2020-715=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2020-715=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2020-715=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2020-715=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2020-715=1 - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2020-715=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2020-715=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2020-715=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2020-715=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2020-715=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2020-715=1 - SUSE Linux Enterprise Desktop 12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2020-715=1 - SUSE Enterprise Storage 5: zypper in -t patch SUSE-Storage-5-2020-715=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2020-715=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (noarch): postgresql10-docs-10.12-1.18.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): libecpg6-10.12-1.18.1 libecpg6-debuginfo-10.12-1.18.1 libpq5-10.12-1.18.1 libpq5-32bit-10.12-1.18.1 libpq5-debuginfo-10.12-1.18.1 libpq5-debuginfo-32bit-10.12-1.18.1 postgresql10-10.12-1.18.1 postgresql10-contrib-10.12-1.18.1 postgresql10-contrib-debuginfo-10.12-1.18.1 postgresql10-debuginfo-10.12-1.18.1 postgresql10-debugsource-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 postgresql10-plperl-10.12-1.18.1 postgresql10-plperl-debuginfo-10.12-1.18.1 postgresql10-plpython-10.12-1.18.1 postgresql10-plpython-debuginfo-10.12-1.18.1 postgresql10-pltcl-10.12-1.18.1 postgresql10-pltcl-debuginfo-10.12-1.18.1 postgresql10-server-10.12-1.18.1 postgresql10-server-debuginfo-10.12-1.18.1 - SUSE OpenStack Cloud 8 (x86_64): libecpg6-10.12-1.18.1 libecpg6-debuginfo-10.12-1.18.1 libpq5-10.12-1.18.1 libpq5-32bit-10.12-1.18.1 libpq5-debuginfo-10.12-1.18.1 libpq5-debuginfo-32bit-10.12-1.18.1 postgresql10-10.12-1.18.1 postgresql10-contrib-10.12-1.18.1 postgresql10-contrib-debuginfo-10.12-1.18.1 postgresql10-debuginfo-10.12-1.18.1 postgresql10-debugsource-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 postgresql10-plperl-10.12-1.18.1 postgresql10-plperl-debuginfo-10.12-1.18.1 postgresql10-plpython-10.12-1.18.1 postgresql10-plpython-debuginfo-10.12-1.18.1 postgresql10-pltcl-10.12-1.18.1 postgresql10-pltcl-debuginfo-10.12-1.18.1 postgresql10-server-10.12-1.18.1 postgresql10-server-debuginfo-10.12-1.18.1 - SUSE OpenStack Cloud 8 (noarch): postgresql10-docs-10.12-1.18.1 - SUSE OpenStack Cloud 7 (s390x x86_64): libecpg6-10.12-1.18.1 libecpg6-debuginfo-10.12-1.18.1 libpq5-10.12-1.18.1 libpq5-32bit-10.12-1.18.1 libpq5-debuginfo-10.12-1.18.1 libpq5-debuginfo-32bit-10.12-1.18.1 postgresql10-10.12-1.18.1 postgresql10-contrib-10.12-1.18.1 postgresql10-contrib-debuginfo-10.12-1.18.1 postgresql10-debuginfo-10.12-1.18.1 postgresql10-debugsource-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 postgresql10-plperl-10.12-1.18.1 postgresql10-plperl-debuginfo-10.12-1.18.1 postgresql10-plpython-10.12-1.18.1 postgresql10-plpython-debuginfo-10.12-1.18.1 postgresql10-pltcl-10.12-1.18.1 postgresql10-pltcl-debuginfo-10.12-1.18.1 postgresql10-server-10.12-1.18.1 postgresql10-server-debuginfo-10.12-1.18.1 - SUSE OpenStack Cloud 7 (noarch): postgresql10-docs-10.12-1.18.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): postgresql10-devel-10.12-1.18.1 postgresql10-devel-debuginfo-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le s390x x86_64): postgresql10-devel-10.12-1.18.1 postgresql10-devel-debuginfo-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): libecpg6-10.12-1.18.1 libecpg6-debuginfo-10.12-1.18.1 libpq5-10.12-1.18.1 libpq5-debuginfo-10.12-1.18.1 postgresql10-10.12-1.18.1 postgresql10-contrib-10.12-1.18.1 postgresql10-contrib-debuginfo-10.12-1.18.1 postgresql10-debuginfo-10.12-1.18.1 postgresql10-debugsource-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 postgresql10-plperl-10.12-1.18.1 postgresql10-plperl-debuginfo-10.12-1.18.1 postgresql10-plpython-10.12-1.18.1 postgresql10-plpython-debuginfo-10.12-1.18.1 postgresql10-pltcl-10.12-1.18.1 postgresql10-pltcl-debuginfo-10.12-1.18.1 postgresql10-server-10.12-1.18.1 postgresql10-server-debuginfo-10.12-1.18.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (x86_64): libpq5-32bit-10.12-1.18.1 libpq5-debuginfo-32bit-10.12-1.18.1 - SUSE Linux Enterprise Server forSAP 12-SP3 (noarch): postgresql10-docs-10.12-1.18.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): libecpg6-10.12-1.18.1 libecpg6-debuginfo-10.12-1.18.1 libpq5-10.12-1.18.1 libpq5-debuginfo-10.12-1.18.1 postgresql10-10.12-1.18.1 postgresql10-contrib-10.12-1.18.1 postgresql10-contrib-debuginfo-10.12-1.18.1 postgresql10-debuginfo-10.12-1.18.1 postgresql10-debugsource-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 postgresql10-plperl-10.12-1.18.1 postgresql10-plperl-debuginfo-10.12-1.18.1 postgresql10-plpython-10.12-1.18.1 postgresql10-plpython-debuginfo-10.12-1.18.1 postgresql10-pltcl-10.12-1.18.1 postgresql10-pltcl-debuginfo-10.12-1.18.1 postgresql10-server-10.12-1.18.1 postgresql10-server-debuginfo-10.12-1.18.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (x86_64): libpq5-32bit-10.12-1.18.1 libpq5-debuginfo-32bit-10.12-1.18.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (noarch): postgresql10-docs-10.12-1.18.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): libecpg6-10.12-1.18.1 libecpg6-debuginfo-10.12-1.18.1 libpq5-10.12-1.18.1 libpq5-32bit-10.12-1.18.1 libpq5-debuginfo-10.12-1.18.1 libpq5-debuginfo-32bit-10.12-1.18.1 postgresql10-10.12-1.18.1 postgresql10-contrib-10.12-1.18.1 postgresql10-contrib-debuginfo-10.12-1.18.1 postgresql10-debuginfo-10.12-1.18.1 postgresql10-debugsource-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 postgresql10-plperl-10.12-1.18.1 postgresql10-plperl-debuginfo-10.12-1.18.1 postgresql10-plpython-10.12-1.18.1 postgresql10-plpython-debuginfo-10.12-1.18.1 postgresql10-pltcl-10.12-1.18.1 postgresql10-pltcl-debuginfo-10.12-1.18.1 postgresql10-server-10.12-1.18.1 postgresql10-server-debuginfo-10.12-1.18.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (noarch): postgresql10-docs-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libecpg6-10.12-1.18.1 libecpg6-debuginfo-10.12-1.18.1 libpq5-10.12-1.18.1 libpq5-debuginfo-10.12-1.18.1 postgresql10-10.12-1.18.1 postgresql10-contrib-10.12-1.18.1 postgresql10-contrib-debuginfo-10.12-1.18.1 postgresql10-debuginfo-10.12-1.18.1 postgresql10-debugsource-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 postgresql10-plperl-10.12-1.18.1 postgresql10-plperl-debuginfo-10.12-1.18.1 postgresql10-plpython-10.12-1.18.1 postgresql10-plpython-debuginfo-10.12-1.18.1 postgresql10-pltcl-10.12-1.18.1 postgresql10-pltcl-debuginfo-10.12-1.18.1 postgresql10-server-10.12-1.18.1 postgresql10-server-debuginfo-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP5 (s390x x86_64): libpq5-32bit-10.12-1.18.1 libpq5-debuginfo-32bit-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP5 (noarch): postgresql10-docs-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP4 (aarch64 ppc64le s390x x86_64): libecpg6-10.12-1.18.1 libecpg6-debuginfo-10.12-1.18.1 libpq5-10.12-1.18.1 libpq5-debuginfo-10.12-1.18.1 postgresql10-10.12-1.18.1 postgresql10-contrib-10.12-1.18.1 postgresql10-contrib-debuginfo-10.12-1.18.1 postgresql10-debuginfo-10.12-1.18.1 postgresql10-debugsource-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 postgresql10-plperl-10.12-1.18.1 postgresql10-plperl-debuginfo-10.12-1.18.1 postgresql10-plpython-10.12-1.18.1 postgresql10-plpython-debuginfo-10.12-1.18.1 postgresql10-pltcl-10.12-1.18.1 postgresql10-pltcl-debuginfo-10.12-1.18.1 postgresql10-server-10.12-1.18.1 postgresql10-server-debuginfo-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP4 (s390x x86_64): libpq5-32bit-10.12-1.18.1 libpq5-debuginfo-32bit-10.12-1.18.1 - SUSE Linux EnterpriseServer 12-SP4 (noarch): postgresql10-docs-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): libecpg6-10.12-1.18.1 libecpg6-debuginfo-10.12-1.18.1 libpq5-10.12-1.18.1 libpq5-debuginfo-10.12-1.18.1 postgresql10-10.12-1.18.1 postgresql10-contrib-10.12-1.18.1 postgresql10-contrib-debuginfo-10.12-1.18.1 postgresql10-debuginfo-10.12-1.18.1 postgresql10-debugsource-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 postgresql10-plperl-10.12-1.18.1 postgresql10-plperl-debuginfo-10.12-1.18.1 postgresql10-plpython-10.12-1.18.1 postgresql10-plpython-debuginfo-10.12-1.18.1 postgresql10-pltcl-10.12-1.18.1 postgresql10-pltcl-debuginfo-10.12-1.18.1 postgresql10-server-10.12-1.18.1 postgresql10-server-debuginfo-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (s390x x86_64): libpq5-32bit-10.12-1.18.1 libpq5-debuginfo-32bit-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (noarch): postgresql10-docs-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP3-BCL (noarch): postgresql10-docs-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): libecpg6-10.12-1.18.1 libecpg6-debuginfo-10.12-1.18.1 libpq5-10.12-1.18.1 libpq5-32bit-10.12-1.18.1 libpq5-debuginfo-10.12-1.18.1 libpq5-debuginfo-32bit-10.12-1.18.1 postgresql10-10.12-1.18.1 postgresql10-contrib-10.12-1.18.1 postgresql10-contrib-debuginfo-10.12-1.18.1 postgresql10-debuginfo-10.12-1.18.1 postgresql10-debugsource-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 postgresql10-plperl-10.12-1.18.1 postgresql10-plperl-debuginfo-10.12-1.18.1 postgresql10-plpython-10.12-1.18.1 postgresql10-plpython-debuginfo-10.12-1.18.1 postgresql10-pltcl-10.12-1.18.1 postgresql10-pltcl-debuginfo-10.12-1.18.1 postgresql10-server-10.12-1.18.1 postgresql10-server-debuginfo-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): libecpg6-10.12-1.18.1 libecpg6-debuginfo-10.12-1.18.1 libpq5-10.12-1.18.1 libpq5-debuginfo-10.12-1.18.1 postgresql10-10.12-1.18.1 postgresql10-contrib-10.12-1.18.1 postgresql10-contrib-debuginfo-10.12-1.18.1 postgresql10-debuginfo-10.12-1.18.1 postgresql10-debugsource-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 postgresql10-plperl-10.12-1.18.1 postgresql10-plperl-debuginfo-10.12-1.18.1 postgresql10-plpython-10.12-1.18.1 postgresql10-plpython-debuginfo-10.12-1.18.1 postgresql10-pltcl-10.12-1.18.1 postgresql10-pltcl-debuginfo-10.12-1.18.1 postgresql10-server-10.12-1.18.1 postgresql10-server-debuginfo-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (s390x x86_64): libpq5-32bit-10.12-1.18.1 libpq5-debuginfo-32bit-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (noarch): postgresql10-docs-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): libecpg6-10.12-1.18.1 libecpg6-debuginfo-10.12-1.18.1 libpq5-10.12-1.18.1 libpq5-32bit-10.12-1.18.1 libpq5-debuginfo-10.12-1.18.1 libpq5-debuginfo-32bit-10.12-1.18.1 postgresql10-10.12-1.18.1 postgresql10-contrib-10.12-1.18.1 postgresql10-contrib-debuginfo-10.12-1.18.1 postgresql10-debuginfo-10.12-1.18.1 postgresql10-debugsource-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 postgresql10-plperl-10.12-1.18.1 postgresql10-plperl-debuginfo-10.12-1.18.1 postgresql10-plpython-10.12-1.18.1 postgresql10-plpython-debuginfo-10.12-1.18.1 postgresql10-pltcl-10.12-1.18.1 postgresql10-pltcl-debuginfo-10.12-1.18.1 postgresql10-server-10.12-1.18.1 postgresql10-server-debuginfo-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP2-BCL (noarch): postgresql10-docs-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): libecpg6-10.12-1.18.1 libecpg6-debuginfo-10.12-1.18.1 libpq5-10.12-1.18.1 libpq5-debuginfo-10.12-1.18.1 postgresql10-10.12-1.18.1 postgresql10-contrib-10.12-1.18.1 postgresql10-contrib-debuginfo-10.12-1.18.1 postgresql10-debuginfo-10.12-1.18.1 postgresql10-debugsource-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 postgresql10-plperl-10.12-1.18.1 postgresql10-plperl-debuginfo-10.12-1.18.1 postgresql10-plpython-10.12-1.18.1 postgresql10-plpython-debuginfo-10.12-1.18.1 postgresql10-pltcl-10.12-1.18.1 postgresql10-pltcl-debuginfo-10.12-1.18.1 postgresql10-server-10.12-1.18.1 postgresql10-server-debuginfo-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (s390x x86_64): libpq5-32bit-10.12-1.18.1 libpq5-debuginfo-32bit-10.12-1.18.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (noarch): postgresql10-docs-10.12-1.18.1 - SUSE Linux Enterprise Desktop 12-SP4 (x86_64): libecpg6-10.12-1.18.1 libecpg6-debuginfo-10.12-1.18.1 libpq5-10.12-1.18.1 libpq5-32bit-10.12-1.18.1 libpq5-debuginfo-10.12-1.18.1 libpq5-debuginfo-32bit-10.12-1.18.1 postgresql10-10.12-1.18.1 postgresql10-debuginfo-10.12-1.18.1 postgresql10-debugsource-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 - SUSE Enterprise Storage 5 (aarch64 x86_64): libecpg6-10.12-1.18.1 libecpg6-debuginfo-10.12-1.18.1 libpq5-10.12-1.18.1 libpq5-debuginfo-10.12-1.18.1 postgresql10-10.12-1.18.1 postgresql10-contrib-10.12-1.18.1 postgresql10-contrib-debuginfo-10.12-1.18.1 postgresql10-debuginfo-10.12-1.18.1 postgresql10-debugsource-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 postgresql10-plperl-10.12-1.18.1 postgresql10-plperl-debuginfo-10.12-1.18.1 postgresql10-plpython-10.12-1.18.1 postgresql10-plpython-debuginfo-10.12-1.18.1 postgresql10-pltcl-10.12-1.18.1 postgresql10-pltcl-debuginfo-10.12-1.18.1 postgresql10-server-10.12-1.18.1 postgresql10-server-debuginfo-10.12-1.18.1 - SUSE Enterprise Storage 5 (x86_64): libpq5-32bit-10.12-1.18.1 libpq5-debuginfo-32bit-10.12-1.18.1 - SUSE Enterprise Storage 5 (noarch): postgresql10-docs-10.12-1.18.1 - HPE Helion Openstack 8 (noarch): postgresql10-docs-10.12-1.18.1 - HPE Helion Openstack 8 (x86_64): libecpg6-10.12-1.18.1 libecpg6-debuginfo-10.12-1.18.1 libpq5-10.12-1.18.1 libpq5-32bit-10.12-1.18.1 libpq5-debuginfo-10.12-1.18.1 libpq5-debuginfo-32bit-10.12-1.18.1 postgresql10-10.12-1.18.1 postgresql10-contrib-10.12-1.18.1 postgresql10-contrib-debuginfo-10.12-1.18.1 postgresql10-debuginfo-10.12-1.18.1 postgresql10-debugsource-10.12-1.18.1 postgresql10-libs-debugsource-10.12-1.18.1 postgresql10-plperl-10.12-1.18.1 postgresql10-plperl-debuginfo-10.12-1.18.1 postgresql10-plpython-10.12-1.18.1 postgresql10-plpython-debuginfo-10.12-1.18.1 postgresql10-pltcl-10.12-1.18.1 postgresql10-pltcl-debuginfo-10.12-1.18.1 postgresql10-server-10.12-1.18.1 postgresql10-server-debuginfo-10.12-1.18.1 References: https://www.suse.com/security/cve/CVE-2020-1720.html https://bugzilla.suse.com/1163985 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Patch for postgresql12 resolves CVE-2021-XXXX with minimal risk, outlining procedures for software refresh.. SUSE Security Update, postgresql10 patch, software maintenance. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Mar 18, 2020 Low SuSE
203

Mageia: 2020-0095 Moderate: PostgreSQL Unauthorized Function Drop

Updated postgresql9.6 and postgresql11 packages fix security vulnerability: The ALTER ... DEPENDS ON EXTENSION sub-commands do not perform authorization checks, which can allow an unprivileged user to drop any function, procedure, materialized view, index, or trigger under certain conditions. This attack is . MGASA-2020-0095 - Updated postgresql packages fix security vulnerability Publication date: 21 Feb 2020 URL: https://advisories.mageia.org/MGASA-2020-0095.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-1720 Updated postgresql9.6 and postgresql11 packages fix security vulnerability: The ALTER ... DEPENDS ON EXTENSION sub-commands do not perform authorization checks, which can allow an unprivileged user to drop any function, procedure, materialized view, index, or trigger under certain conditions. This attack is possible if an administrator has installed an extension and an unprivileged user can CREATE, or an extension owner either executes DROP EXTENSION predictably or can be convinced to execute DROP EXTENSION (CVE-2020-1720). References: - https://bugs.mageia.org/show_bug.cgi?id=26196 - https://www.postgresql.org/about/news/postgresql-122-117-1012-9617-9521-and-9426-released-2011/ - https://www.cve.org/CVERecord?id=CVE-2020-1720 SRPMS: - 7/core/postgresql9.6-9.6.17-1.mga7 - 7/core/postgresql11-11.7-1.mga7 . Updates to the PostgreSQL package resolve a security flaw that allows unauthorized individuals to eliminate functions in specific scenarios.. PostgreSQL Security, Mageia Update, Security Advisory, Unprivileged User Exploit. . LinuxSecurity.com Team

Calendar%202 Feb 21, 2020 Mageia
197

Debian 8 Jessie: DLA-2105-1 Critical: PostgreSQL Access Control Fix

Tom Lane discovered that "ALTER ... DEPENDS ON EXTENSION" sub commands in the PostgreSQL database did not perform authorisation checks. For Debian 8 "Jessie", this problem has been fixed in version . Package : postgresql-9.4 Version : 9.4.26-0+deb8u1 CVE ID : CVE-2020-1720 Tom Lane discovered that "ALTER ... DEPENDS ON EXTENSION" sub commands in the PostgreSQL database did not perform authorisation checks. For Debian 8 "Jessie", this problem has been fixed in version 9.4.26-0+deb8u1. We recommend that you upgrade your postgresql-9.4_9.4.26-0+deb8u1 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . To enhance the security of your Debian 8 Jessie system, it is essential to update your postgresql-9.4 package to address significant authorization verification vulnerabilities.. Debian Security Update, PostgreSQL Authorization, Debian LTS Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 17, 2020 Critical Debian LTS
100

SUSE: 2018:3377-1 Important: Fixes for Postgresql96 Security Issues

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for postgresql96 ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:3377-1 Rating: important References: #1104199 #1104202 Cross-References: CVE-2018-10915 CVE-2018-10925 Affected Products: SUSE OpenStack Cloud 7 SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Linux Enterprise Server 12-LTSS SUSE Linux Enterprise Desktop 12-SP3 SUSE Enterprise Storage 4 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for postgresql96 to 9.6.10 fixes the following issues: These security issues were fixed: - CVE-2018-10915: libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could have bypassed client-side connection security features, obtain access to higher privileged connections or potentially cause other impact SQL injection, by causing the PQescape() functions to malfunction (bsc#1104199) - CVE-2018-10925: Add missing authorization check on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "CREATE TABLE" privileges could have exploited this to read arbitrary bytes server memory. If the attacker also had certain "INSERT" and limited "UPDATE" privileges to a particular table,they could have exploited this to update other columns in the same table (bsc#1104202) For addition details please see https://www.postgresql.org/docs/9.6/release-9-6-10.html Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2018-2427=1 - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2018-2427=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2018-2427=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2018-2427=1 - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2018-2427=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2018-2427=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2018-2427=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2018-2427=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2018-2427=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2018-2427=1 Package List: - SUSE OpenStack Cloud 7 (s390x x86_64): postgresql96-9.6.10-3.22.7 postgresql96-contrib-9.6.10-3.22.7 postgresql96-contrib-debuginfo-9.6.10-3.22.7 postgresql96-debuginfo-9.6.10-3.22.7 postgresql96-debugsource-9.6.10-3.22.7 postgresql96-libs-debugsource-9.6.10-3.22.1 postgresql96-server-9.6.10-3.22.7 postgresql96-server-debuginfo-9.6.10-3.22.7 - SUSE OpenStack Cloud 7 (noarch): postgresql96-docs-9.6.10-3.22.7 - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): postgresql96-devel-9.6.10-3.22.1 postgresql96-devel-debuginfo-9.6.10-3.22.1 postgresql96-libs-debugsource-9.6.10-3.22.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): postgresql96-9.6.10-3.22.7 postgresql96-contrib-9.6.10-3.22.7 postgresql96-contrib-debuginfo-9.6.10-3.22.7 postgresql96-debuginfo-9.6.10-3.22.7 postgresql96-debugsource-9.6.10-3.22.7 postgresql96-libs-debugsource-9.6.10-3.22.1 postgresql96-server-9.6.10-3.22.7 postgresql96-server-debuginfo-9.6.10-3.22.7 - SUSE Linux Enterprise Server for SAP 12-SP2 (noarch): postgresql96-docs-9.6.10-3.22.7 - SUSE Linux Enterprise Server for SAP 12-SP1 (ppc64le x86_64): postgresql96-9.6.10-3.22.7 postgresql96-contrib-9.6.10-3.22.7 postgresql96-contrib-debuginfo-9.6.10-3.22.7 postgresql96-debuginfo-9.6.10-3.22.7 postgresql96-debugsource-9.6.10-3.22.7 postgresql96-libs-debugsource-9.6.10-3.22.1 postgresql96-server-9.6.10-3.22.7 postgresql96-server-debuginfo-9.6.10-3.22.7 - SUSE Linux Enterprise Server for SAP 12-SP1 (noarch): postgresql96-docs-9.6.10-3.22.7 - SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le s390x x86_64): postgresql96-9.6.10-3.22.7 postgresql96-contrib-9.6.10-3.22.7 postgresql96-contrib-debuginfo-9.6.10-3.22.7 postgresql96-debuginfo-9.6.10-3.22.7 postgresql96-debugsource-9.6.10-3.22.7 postgresql96-libs-debugsource-9.6.10-3.22.1 postgresql96-server-9.6.10-3.22.7 postgresql96-server-debuginfo-9.6.10-3.22.7 - SUSE Linux Enterprise Server 12-SP3 (noarch): postgresql96-docs-9.6.10-3.22.7 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): postgresql96-9.6.10-3.22.7 postgresql96-contrib-9.6.10-3.22.7 postgresql96-contrib-debuginfo-9.6.10-3.22.7 postgresql96-debuginfo-9.6.10-3.22.7 postgresql96-debugsource-9.6.10-3.22.7 postgresql96-libs-debugsource-9.6.10-3.22.1 postgresql96-server-9.6.10-3.22.7 postgresql96-server-debuginfo-9.6.10-3.22.7 - SUSE Linux Enterprise Server 12-SP2-LTSS (noarch): postgresql96-docs-9.6.10-3.22.7 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): postgresql96-9.6.10-3.22.7 postgresql96-contrib-9.6.10-3.22.7 postgresql96-contrib-debuginfo-9.6.10-3.22.7 postgresql96-debuginfo-9.6.10-3.22.7 postgresql96-debugsource-9.6.10-3.22.7 postgresql96-libs-debugsource-9.6.10-3.22.1 postgresql96-server-9.6.10-3.22.7 postgresql96-server-debuginfo-9.6.10-3.22.7 - SUSE Linux Enterprise Server 12-SP1-LTSS (noarch): postgresql96-docs-9.6.10-3.22.7 - SUSE Linux Enterprise Server 12-LTSS (ppc64le s390x x86_64): postgresql96-9.6.10-3.22.7 postgresql96-contrib-9.6.10-3.22.7 postgresql96-contrib-debuginfo-9.6.10-3.22.7 postgresql96-debuginfo-9.6.10-3.22.7 postgresql96-debugsource-9.6.10-3.22.7 postgresql96-server-9.6.10-3.22.7 postgresql96-server-debuginfo-9.6.10-3.22.7 - SUSE Linux Enterprise Server 12-LTSS (noarch): postgresql96-docs-9.6.10-3.22.7 - SUSE Linux Enterprise Server 12-LTSS (s390x): postgresql96-libs-debugsource-9.6.10-3.22.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): postgresql96-9.6.10-3.22.7 postgresql96-debuginfo-9.6.10-3.22.7 postgresql96-debugsource-9.6.10-3.22.7 postgresql96-libs-debugsource-9.6.10-3.22.1 - SUSE Enterprise Storage 4 (x86_64): postgresql96-9.6.10-3.22.7 postgresql96-contrib-9.6.10-3.22.7 postgresql96-contrib-debuginfo-9.6.10-3.22.7 postgresql96-debuginfo-9.6.10-3.22.7 postgresql96-debugsource-9.6.10-3.22.7 postgresql96-libs-debugsource-9.6.10-3.22.1 postgresql96-server-9.6.10-3.22.7 postgresql96-server-debuginfo-9.6.10-3.22.7 - SUSE Enterprise Storage 4 (noarch): postgresql96-docs-9.6.10-3.22.7 References: https://www.suse.com/security/cve/CVE-2018-10915.html https://www.suse.com/security/cve/CVE-2018-10925.html https://bugzilla.suse.com/1104199 https://bugzilla.suse.com/1104202 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . Crucial enhancements for PostgreSQL 9.6 address security flaws encompassing authentication validations and SQL injection issues.. SUSE Postgresql Update, Security Patch SUSE, Postgresql Vulnerability Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 24, 2018 Important SuSE
202

openSUSE Leap 15.0: 2018:2599-1 Moderate: PostgreSQL10 Security Fixes

An update that fixes three vulnerabilities is now available.. openSUSE Security Update: Security update for postgresql10 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2599-1 Rating: moderate References: #1091610 #1104199 #1104202 Cross-References: CVE-2018-10915 CVE-2018-10925 CVE-2018-1115 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for postgresql10 fixes the following issues: PostgreSQL 10 was updated to 10.5: - https://www.postgresql.org/about/news/postgresql-104-969-9513-9418-and-9323-released-1851/ - https://www.postgresql.org/docs/10/release-10-5.html A dump/restore is not required for those running 10.X. However, if you use the adminpack extension, you should update it as per the first changelog entry below. Also, if the function marking mistakes mentioned in the second and third changelog entries below affect you, you will want to take steps to correct your database catalogs. Security issues fixed: - CVE-2018-1115: Remove public execute privilege from contrib/adminpack's pg_logfile_rotate() function pg_logfile_rotate() is a deprecated wrapper for the core function pg_rotate_logfile(). When that function was changed to rely on SQL privileges for access control rather than a hard-coded superuser check, pg_logfile_rotate() should have been updated as well, but the need for this was missed. Hence, if adminpack is installed, any user could request a logfile rotation, creating a minor security issue. After installing this update, administrators should update adminpack by performing ALTER EXTENSION adminpack UPDATE in each database in which adminpack is installed (bsc#1091610). - CVE-2018-10915: libpq failed to properly resetits internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could have bypassed client-side connection security features, obtain access to higher privileged connections or potentially cause other impact SQL injection, by causing the PQescape() functions to malfunction (bsc#1104199) - CVE-2018-10925: Add missing authorization check on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "CREATE TABLE" privileges could have exploited this to read arbitrary bytes server memory. If the attacker also had certain "INSERT" and limited "UPDATE" privileges to a particular table, they could have exploited this to update other columns in the same table (bsc#1104202). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-955=1 Package List: - openSUSE Leap 15.0 (i586 x86_64): libecpg6-10.5-lp150.3.3.1 libecpg6-debuginfo-10.5-lp150.3.3.1 libpq5-10.5-lp150.3.3.1 libpq5-debuginfo-10.5-lp150.3.3.1 postgresql10-10.5-lp150.3.3.1 postgresql10-contrib-10.5-lp150.3.3.1 postgresql10-contrib-debuginfo-10.5-lp150.3.3.1 postgresql10-debuginfo-10.5-lp150.3.3.1 postgresql10-debugsource-10.5-lp150.3.3.1 postgresql10-devel-10.5-lp150.3.3.1 postgresql10-devel-debuginfo-10.5-lp150.3.3.1 postgresql10-plperl-10.5-lp150.3.3.1 postgresql10-plperl-debuginfo-10.5-lp150.3.3.1 postgresql10-plpython-10.5-lp150.3.3.1 postgresql10-plpython-debuginfo-10.5-lp150.3.3.1 postgresql10-pltcl-10.5-lp150.3.3.1 postgresql10-pltcl-debuginfo-10.5-lp150.3.3.1 postgresql10-server-10.5-lp150.3.3.1 postgresql10-server-debuginfo-10.5-lp150.3.3.1 postgresql10-test-10.5-lp150.3.3.1 - openSUSE Leap 15.0 (x86_64): libecpg6-32bit-10.5-lp150.3.3.1 libecpg6-32bit-debuginfo-10.5-lp150.3.3.1 libpq5-32bit-10.5-lp150.3.3.1 libpq5-32bit-debuginfo-10.5-lp150.3.3.1 - openSUSE Leap 15.0 (noarch): postgresql10-docs-10.5-lp150.3.3.1 References: https://www.suse.com/security/cve/CVE-2018-10915.html https://www.suse.com/security/cve/CVE-2018-10925.html https://www.suse.com/security/cve/CVE-2018-1115.html https://bugzilla.suse.com/1091610 https://bugzilla.suse.com/1104199 https://bugzilla.suse.com/1104202 -- . A recent patch for Fedora tackles significant MySQL vulnerabilities while improving data security throughout various software platforms.. openSUSE Security Update, PostgreSQL 10, patch instructions. . LinuxSecurity.com Team

Calendar%202 Sep 04, 2018 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200