Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
98

RHEL PostgreSQL: RHSA-2020:5620-01 Important: Security Update

An update for the postgresql:12 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: postgresql:12 security update Advisory ID: RHSA-2020:5620-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:5620 Issue date: 2020-12-17 CVE Names: CVE-2020-1720 CVE-2020-14349 CVE-2020-14350 CVE-2020-25694 CVE-2020-25695 CVE-2020-25696 ==================================================================== 1. Summary: An update for the postgresql:12 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: PostgreSQL is an advanced object-relational database management system (DBMS). The following packages have been upgraded to a later upstream version: postgresql (12.5). Security Fix(es): * postgresql: Reconnection can downgrade connection security settings (CVE-2020-25694) * postgresql: Multiple features escape "security restricted operation" sandbox (CVE-2020-25695) * postgresql: Uncontrolled search path element in logical replication (CVE-2020-14349) * postgresql: Uncontrolled search path element in CREATE EXTENSION (CVE-2020-14350) * postgresql: psql's gset allows overwriting specially treated variables (CVE-2020-25696) * postgresql: ALTER ... DEPENDS ON EXTENSION is missingauthorization checks (CVE-2020-1720) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 If the postgresql service is running, it will be automatically restarted after installing this update. 5. Bugs fixed (https://bugzilla.redhat.com/): 1798852 - CVE-2020-1720 postgresql: ALTER ... DEPENDS ON EXTENSION is missing authorization checks 1865744 - CVE-2020-14349 postgresql: Uncontrolled search path element in logical replication 1865746 - CVE-2020-14350 postgresql: Uncontrolled search path element in CREATE EXTENSION 1894423 - CVE-2020-25694 postgresql: Reconnection can downgrade connection security settings 1894425 - CVE-2020-25695 postgresql: Multiple features escape "security restricted operation" sandbox 1894430 - CVE-2020-25696 postgresql: psql's gset allows overwriting specially treated variables 6. Package List: Red Hat Enterprise Linux AppStream (v.8): Source: pgaudit-1.4.0-4.module+el8.3.0+9042+664538f4.src.rpm postgres-decoderbufs-0.10.0-2.module+el8.3.0+9042+664538f4.src.rpm postgresql-12.5-1.module+el8.3.0+9042+664538f4.src.rpm aarch64: pgaudit-1.4.0-4.module+el8.3.0+9042+664538f4.aarch64.rpm pgaudit-debuginfo-1.4.0-4.module+el8.3.0+9042+664538f4.aarch64.rpm pgaudit-debugsource-1.4.0-4.module+el8.3.0+9042+664538f4.aarch64.rpm postgres-decoderbufs-0.10.0-2.module+el8.3.0+9042+664538f4.aarch64.rpm postgres-decoderbufs-debuginfo-0.10.0-2.module+el8.3.0+9042+664538f4.aarch64.rpm postgres-decoderbufs-debugsource-0.10.0-2.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-contrib-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-contrib-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-debugsource-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-docs-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-docs-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-plperl-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-plperl-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-plpython3-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-plpython3-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-pltcl-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-pltcl-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-server-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-server-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-server-devel-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-server-devel-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-static-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-test-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-test-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-upgrade-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-upgrade-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-upgrade-devel-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm postgresql-upgrade-devel-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.aarch64.rpm noarch: postgresql-test-rpm-macros-12.5-1.module+el8.3.0+9042+664538f4.noarch.rpm ppc64le: pgaudit-1.4.0-4.module+el8.3.0+9042+664538f4.ppc64le.rpm pgaudit-debuginfo-1.4.0-4.module+el8.3.0+9042+664538f4.ppc64le.rpm pgaudit-debugsource-1.4.0-4.module+el8.3.0+9042+664538f4.ppc64le.rpm postgres-decoderbufs-0.10.0-2.module+el8.3.0+9042+664538f4.ppc64le.rpm postgres-decoderbufs-debuginfo-0.10.0-2.module+el8.3.0+9042+664538f4.ppc64le.rpm postgres-decoderbufs-debugsource-0.10.0-2.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-contrib-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-contrib-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-debugsource-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-docs-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-docs-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-plperl-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-plperl-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-plpython3-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-plpython3-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-pltcl-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-pltcl-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-server-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-server-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-server-devel-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-server-devel-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-static-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-test-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-test-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-upgrade-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-upgrade-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-upgrade-devel-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm postgresql-upgrade-devel-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.ppc64le.rpm s390x: pgaudit-1.4.0-4.module+el8.3.0+9042+664538f4.s390x.rpm pgaudit-debuginfo-1.4.0-4.module+el8.3.0+9042+664538f4.s390x.rpm pgaudit-debugsource-1.4.0-4.module+el8.3.0+9042+664538f4.s390x.rpm postgres-decoderbufs-0.10.0-2.module+el8.3.0+9042+664538f4.s390x.rpm postgres-decoderbufs-debuginfo-0.10.0-2.module+el8.3.0+9042+664538f4.s390x.rpm postgres-decoderbufs-debugsource-0.10.0-2.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-contrib-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-contrib-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-debugsource-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-docs-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-docs-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-plperl-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-plperl-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-plpython3-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-plpython3-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-pltcl-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-pltcl-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-server-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-server-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-server-devel-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-server-devel-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-static-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-test-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-test-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-upgrade-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-upgrade-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-upgrade-devel-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm postgresql-upgrade-devel-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.s390x.rpm x86_64: pgaudit-1.4.0-4.module+el8.3.0+9042+664538f4.x86_64.rpm pgaudit-debuginfo-1.4.0-4.module+el8.3.0+9042+664538f4.x86_64.rpm pgaudit-debugsource-1.4.0-4.module+el8.3.0+9042+664538f4.x86_64.rpm postgres-decoderbufs-0.10.0-2.module+el8.3.0+9042+664538f4.x86_64.rpm postgres-decoderbufs-debuginfo-0.10.0-2.module+el8.3.0+9042+664538f4.x86_64.rpm postgres-decoderbufs-debugsource-0.10.0-2.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-contrib-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-contrib-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-debugsource-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-docs-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-docs-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-plperl-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-plperl-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-plpython3-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-plpython3-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-pltcl-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-pltcl-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-server-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-server-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-server-devel-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-server-devel-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-static-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-test-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-test-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-upgrade-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-upgrade-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-upgrade-devel-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm postgresql-upgrade-devel-debuginfo-12.5-1.module+el8.3.0+9042+664538f4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-1720 https://access.redhat.com/security/cve/CVE-2020-14349 https://access.redhat.com/security/cve/CVE-2020-14350 https://access.redhat.com/security/cve/CVE-2020-25694 https://access.redhat.com/security/cve/CVE-2020-25695 https://access.redhat.com/security/cve/CVE-2020-25696 https://access.redhat.com/security/updates/classification/#important https://www.postgresql.org/docs/12/release-12-2.html https://www.postgresql.org/docs/12/release-12-3.html https://www.postgresql.org/docs/12/release-12-4.html https://www.postgresql.org/docs/12/release-12-5.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBX9uAVtzjgjWX9erEAQgmqhAAip8RwhLxjtl1gQIhgZKEaCgXekTFYtJj B+GdNU37hNQclNSHrsTn9/99FMo0i+8ACsdejygMAgrBHj85LK/2TkvX4TBoX/Gu g6+4rncBFBtgp6CPJSjBydcFrwCaI8LHqdmA+7mIIDHEPJBKVdGtEKZ8cm6Bug2L m4ye1iWH+OxlKW0V871E3vQ4HqGL031Rwgy3+KyRmETeNfVKLrbO9VM5/9XyjoE5 02diSTQInMcMSfOLWb08l5GSsAjsMdSEvYHK6m7PHbKXdq00mjjD4ooLqjAFP96u 4LX11dhNHlz6EEZ1JMSQ5SoxWm/B7inKRxLFcPSNODHQjK3qPkS6zpu5Drp9fq6t XRiQkdrE8vhnHbEWJ0a05WFldZ9YynkL1Kz2SeeljWi2n2dk4dvjF9GStccDsLra AADkkQmyaQ/GMxGGhZ88DaArG1GJVDsHSgJDpg9g2jaovbmqvSbseFNVHXJIcHpO Png87xC2LU7ZDUnpbjNIt8DZI+Yg2vLYX8Psx1Xfcl1mqBQY5YyRR9IG/7HJWESn cN+T8FeLN+/e5x0/R1/5/GBAVHkLjNhStY0xvo1ga4trtzIPYW0n2nxJy1/Pwljf 8FxKyrEOfyAlwC3I3Ot6t/Khg3RFOf5taRn3ff4S1al51aiXYRsEgrL7XiJSzaNO YmboFvTqTBc=jogS -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical patch has been released for Red Hat's postgresql:12 module, classified as a significant security enhancement.. PostgreSQL Security Update, Red Hat Advisory, Database Module Patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 17, 2020 Important Red Hat
172

Ubuntu 20.10: USN-4633-1 Critical: PostgreSQL Connection Issues

Several security issues were fixed in PostgreSQL.. =========================================================================Ubuntu Security Notice USN-4633-1 November 17, 2020 postgresql-10, postgresql-12, postgresql-9.5 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in PostgreSQL. Software Description: - postgresql-12: Object-relational SQL database - postgresql-10: Object-relational SQL database - postgresql-9.5: Object-relational SQL database Details: Peter Eisentraut discovered that PostgreSQL incorrectly handled connection security settings. Client applications could possibly be connecting with certain security parameters dropped, contrary to expectations. (CVE-2020-25694) Etienne Stalmans discovered that PostgreSQL incorrectly handled the security restricted operation sandbox. An authenticated remote attacker could possibly use this issue to execute arbitrary SQL functions as a superuser. (CVE-2020-25695) Nick Cleaton discovered that PostgreSQL incorrectly handled the \gset meta-command. A remote attacker with a compromised server could possibly use this issue to execute arbitrary code. (CVE-2020-25696) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: postgresql-12 12.5-0ubuntu0.20.10.1 Ubuntu 20.04 LTS: postgresql-12 12.5-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: postgresql-10 10.15-0ubuntu0.18.04.1 Ubuntu 16.04 LTS: postgresql-9.5 9.5.24-0ubuntu0.16.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart PostgreSQL to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4633-1 CVE-2020-25694, CVE-2020-25695, CVE-2020-25696 Package Information: https://launchpad.net/ubuntu/+source/postgresql-12/12.5-0ubuntu0.20.10.1 https://launchpad.net/ubuntu/+source/postgresql-12/12.5-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/postgresql-10/10.15-0ubuntu0.18.04.1 https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.24-0ubuntu0.16.04.1 . Several vulnerabilities addressed in PostgreSQL for various Ubuntu versions. Immediate updates recommended for affected installations. Discover more details!. PostgreSQL Security Issues, Ubuntu Security Advisory, PostgreSQL Update Instructions. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 17, 2020 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here