Several security issues were fixed in PostgreSQL.. ========================================================================== Ubuntu Security Notice USN-7132-1 December 02, 2024 postgresql-12, postgresql-14, postgresql-16 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in PostgreSQL. Software Description: - postgresql-16: Object-relational SQL database - postgresql-14: Object-relational SQL database - postgresql-12: Object-relational SQL database Details: It was discovered that PostgreSQL incorrectly tracked tables with row security. A remote attacker could possibly use this issue to perform forbidden reads and modifications. (CVE-2024-10976) Jacob Champion discovered that PostgreSQL clients used untrusted server error messages. An attacker that is able to intercept network communications could possibly use this issue to inject error messages that could be interpreted as valid query results. (CVE-2024-10977) Tom Lane discovered that PostgreSQL incorrectly handled certain privilege assignments. A remote attacker could possibly use this issue to view or change different rows from those intended. (CVE-2024-10978) Coby Abrams discovered that PostgreSQL incorrectly handled environment variables. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2024-10979) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 postgresql-16 16.6-0ubuntu0.24.10.1 postgresql-client-16 16.6-0ubuntu0.24.10.1 Ubuntu 24.04 LTS postgresql-16 16.6-0ubuntu0.24.04.1 postgresql-client-16 16.6-0ubuntu0.24.04.1 Ubuntu 22.04 LTS postgresql-14 14.15-0ubuntu0.22.04.1 postgresql-client-14 14.15-0ubuntu0.22.04.1 Ubuntu 20.04 LTS postgresql-12 12.22-0ubuntu0.20.04.1 postgresql-client-12 12.22-0ubuntu0.20.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart PostgreSQL to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7132-1 CVE-2024-10976, CVE-2024-10977, CVE-2024-10978, CVE-2024-10979 Package Information: https://launchpad.net/ubuntu/+source/postgresql-16/16.6-0ubuntu0.24.10.1 https://launchpad.net/ubuntu/+source/postgresql-16/16.6-0ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/postgresql-14/14.15-0ubuntu0.22.04.1 . A security update for MySQL addressed various vulnerabilities across numerous Debian iterations as outlined in DSA-5012-1.. PostgreSQL Security, Ubuntu Updates, Database Vulnerability Fix. . Severity: Critical. LinuxSecurity.com Team
Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.12.5 on Red Hat Enterprise Linux 8 from Red Hat Container Registry. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenShift Data Foundation 4.12.5 security and bug fix update Advisory ID: RHSA-2023:4287-01 Product: Red Hat OpenShift Data Foundation Advisory URL: https://access.redhat.com/errata/RHSA-2023:4287 Issue date: 2023-07-26 CVE Names: CVE-2020-24736 CVE-2023-1667 CVE-2023-2283 CVE-2023-3089 CVE-2023-24329 CVE-2023-26604 ===================================================================== 1. Summary: Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.12.5 on Red Hat Enterprise Linux 8 from Red Hat Container Registry. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Container Platform. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multicloud data management service with an S3 compatible API. Security Fix(es): * openshift: OCP & FIPS mode (CVE-2023-3089) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in theReferences section. Bug Fix(es): * Previously, OpenShift Data Foundation was not setting up the correct user interface (UI) plugin version in its generated `plugin-manifest.json` during the upgrades. This resulted in OpenShift Data Foundation not showing up the refresh pop-up because it could not detect the change in version. With this fix, the correct plugin version is set up to enable OpenShift Container Platform console to detect upgrades and trigger the refresh pop-up dialog box. As a result, a refresh pop-up shows up and when clicked, it loads the new UI content for the upgraded OpenShift Data Foundation. (BZ#2214575) * Previously, in MultiCloud Object Gateway (MCG), there was a significant degradation in performance with read and write operations of small objects. The degradation was because the Remote Procedure Calls (RPC) between the MCG endpoint and the core that were required to be cached missed the cache each time causing an RPC message between the endpoint and the core per each operation. With this fix, the lookup in cache is fixed so that the existing data is found and not queried at each operation. (BZ#2215978) * Previously, there were repeated crashes of the MultiCloud Object Gateway (MCG) Operator because the operator collided with the updates to the structure when it was trying to print a debug message regarding an internal structure in the MCG Operator. With this release, the print is fixed so that there are no collisions, thereby avoiding the repeated crashes fo MCG Operator. (BZ#2216402) All users of Red Hat OpenShift Data Foundation are advised to upgrade to these updated images, which provide these bug fixes. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2210475 - When collecting Must-gather logs shows /usr/bin/gather_ceph_resources: line 341: jq: command notfound 2211592 - [ODF 4.12] [GSS] unknown parameter name "FORCE_OSD_REMOVAL" 2212085 - CVE-2023-3089 openshift: OCP & FIPS mode 2213452 - Set ??maxOpenShiftVersion to block OpenShift that didn't upgrade ODF version 2214575 - ODF dashboard crashes when OCP and ODF are upgraded 2216402 - [backport to 4.12.z] noobaa-operator pod shows multiple restarts 2224246 - [Major Incident] CVE-2023-3089 mcg-operator-container: openshift: OCP & FIPS mode [openshift-data-foundation-4.12] 5. References: https://access.redhat.com/security/cve/CVE-2020-24736 https://access.redhat.com/security/cve/CVE-2023-1667 https://access.redhat.com/security/cve/CVE-2023-2283 https://access.redhat.com/security/cve/CVE-2023-3089 https://access.redhat.com/security/cve/CVE-2023-24329 https://access.redhat.com/security/cve/CVE-2023-26604 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2023-001 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJkwX/OAAoJENzjgjWX9erEPf0P/2LN/vkUNrfSZD25KV1e4K44 8Sd2RBx6iUO4Yy+O+AwT4t1lwebJQe0ZR3KkIbRreUFW3vyjuNN58O2uRtr5qYxR CVRynMzVG2jPpCGHaJ7+vjAVfqFaOU0koxF+Dan+J8+bb6UNGeGciaDCUxKm0r8o Y4uv9CwBahVpFoa68X0ZRsym69MYJSlPKJFweUOqownJ1OfMIKf/4UPBoex6jkUF wNQtImiBTbAxHkS3IoLkI2u0ABVPxIa3Aqz9b1U4jSet3ESj4X4304smnSZFCMLM uB3QnP0HtngNqpVmd3bvS94G8zWmIDpwK7K+uA9fLNpSj4n3hkb2SFQdmNzdA2EB 1F5ZdfBBJEe7nTiz4UoSrEC6s71qlJwuJgf/8VXOEwwXE2T+M2MG2WnzI4TXuBDb BzwEfwOkNw7UA1E8SQYwcRDKvhEyy81OilFcpNIos/89zDv0ZY6Uwq70wKa9o2zn wtU80K6oH9UH3AOTpXah0ykTvrS8UHSBYzZfOWihp4eUtQQsVDtfdT0+aJuvGC+8 XHXAw3QfmZYhtoZG/MrU50LSyZ7m5jaVmJdLNSFLPA6WGUJzCeeZioAdwI7uMYpJ EYDQRcIfvZPhhLqWonNQPAe2fi4tuGSWvTAOZhX8zlOMHN2Li1b4D10uBq+y66cy 9FDStP1Y8zQu3lR3UPBF =UROy -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.11.9 on Red Hat Enterprise Linux 8 from Red Hat Container Registry. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenShift Data Foundation 4.11.9 security and bug fix update Advisory ID: RHSA-2023:4238-01 Product: Red Hat OpenShift Data Foundation Advisory URL: https://access.redhat.com/errata/RHSA-2023:4238 Issue date: 2023-07-20 CVE Names: CVE-2020-24736 CVE-2022-2795 CVE-2022-36227 CVE-2022-40023 CVE-2023-1667 CVE-2023-2283 CVE-2023-2491 CVE-2023-3089 CVE-2023-24329 CVE-2023-26604 CVE-2023-27535 ==================================================================== 1. Summary: Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.11.9 on Red Hat Enterprise Linux 8 from Red Hat Container Registry. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multi-cloud data management service with an S3-compatible API. Security Fix(es): * openshift: OCP & FIPS mode (CVE-2023-3089) For more details about the security issue(s), including the impact,a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * [Backport-4.11.z][KMS][VAULT] Storage cluster remains in 'Progressing' state during deployment with storage class encryption, despite all pods being up and running. (BZ#2209254) * Set ââmaxOpenShiftVersion to block OpenShift that didn't upgrade ODF version (BZ#2213451) All users of Red Hat OpenShift Data Foundation are advised to upgrade to these updated images, which provide these bug fixes. 3. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2209254 - [Backport-4.11.z][KMS][VAULT] Storage cluster remains in 'Progressing' state during deployment with storage class encryption, despite all pods being up and running. 2211594 - [ODF 4.11] [GSS] unknown parameter name "FORCE_OSD_REMOVAL" 2212085 - CVE-2023-3089 openshift: OCP & FIPS mode 2213451 - Set ??maxOpenShiftVersion to block OpenShift that didn't upgrade ODF version 2224268 - [Major Incident] CVE-2023-3089 mcg-operator-container: openshift: OCP & FIPS mode [openshift-data-foundation-4.11] 5. References: https://access.redhat.com/security/cve/CVE-2020-24736 https://access.redhat.com/security/cve/CVE-2022-2795 https://access.redhat.com/security/cve/CVE-2022-36227 https://access.redhat.com/security/cve/CVE-2022-40023 https://access.redhat.com/security/cve/CVE-2023-1667 https://access.redhat.com/security/cve/CVE-2023-2283 https://access.redhat.com/security/cve/CVE-2023-2491 https://access.redhat.com/security/cve/CVE-2023-3089 https://access.redhat.com/security/cve/CVE-2023-24329 https://access.redhat.com/security/cve/CVE-2023-26604 https://access.redhat.com/security/cve/CVE-2023-27535 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2023-001 6. Contact: The Red Hat security contactis . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJkuYUSAAoJENzjgjWX9erEHFUP/Aoi+Jf/yfXTimePl9G7nYHh OCmC/5nLd2eHzI2zvvJi/1OOsHn6gNESbmDA8L/eWpUnUaw3rCqJA+uSWmHxqOs8 JC/nUQSNpZ4qBr6dY+srckbvEW68xliPD7ypcIe0VTl+d9vmWmcQ3OraUygGydUA uGHKS16/8VUK7wpca2A49bUMfIqWVCEOjYpsOX1tXmRfMKxowZ8cz+gTIR3iEGb9 TE9zx6ZOGzC75NoLStbgdmgCypLIKkVrrPV61vI6Ux/hEEKp2a7tdtMEyaS7oh2q lAm/WV6oyvGZinUZ8Oy95erNGq8aoS7XKrskkqAiRYempFeEf02haBEyB0ocqAH/ 8vO1QtkzTWawNjkYYi8XS+HN6WawUHXPdl6Au0MFbeTQf9HfEiWkL369PNVo/1m3 8rPZbbxi7hqQrJGdlFCh91DQXqWp+tcKBgGW0ybALI2dQe+QQhyOV56xSkd1Q4Xk 6ytK2Mm493eqZRc6yQApCChyggRO3TfHs+JGAE4tKXmmIlPwFosd/6dpjzwMDB1D Dd8iHrkYjG4+/mErMJZAc0NJsohr7yYkmJuzs2NI//RThy3RtivdnpPTkEQJwpvN oM9xyvoli9BqnH6ec3asWops2Z5TNhlmc71fcf2nXCP8U4vjK7lKlPtUSL8KGGGY pHZiOudZ33xTkcgYgNGn =s5RK -----END PGP SIGNATURE----- -- RHSA-announce mailing list
The evolution-data-server package has been updated to the latest stable upstream version.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-320 2006-04-17 ---------------------------------------------------------------------Product : Fedora Core 5 Name : evolution-data-server Version : 1.6.1 Release : 1.fc5.2 Summary : Backend data server for evolution Description : The evolution-data-server package provides a unified backend for programs that work with contacts, tasks, and calendar information. It was originally developed for Evolution (hence the name), but is now used by other packages. ---------------------------------------------------------------------Update Information: The evolution-data-server package has been updated to the latest stable upstream version. ---------------------------------------------------------------------* Mon Apr 10 2006 Matthias Clasen - 1.6.1-1.fc5.2 - Fix a multilib conflict * Mon Apr 10 2006 Matthias Clasen - 1.6.1-1.fc5.1 - Update to 1.6.1 ---------------------------------------------------------------------This update can be downloaded from: e502b5abaac3c21c4ac828fa37231fdacffcea06 SRPMS/evolution-data-server-1.6.1-1.fc5.2.src.rpm eaa52ebe634c184a7fe14a241ba1a2564b2aaf11 ppc/evolution-data-server-1.6.1-1.fc5.2.ppc.rpm 41dfb0a179723a6dd052c162807a6b4ea9afcec9 ppc/evolution-data-server-devel-1.6.1-1.fc5.2.ppc.rpm 4df6a7cebac6e078698037390d0c96155c682ea1 ppc/debug/evolution-data-server-debuginfo-1.6.1-1.fc5.2.ppc.rpm 593ed3daff3b2f628fcb9b1e047301206a7045a0 x86_64/evolution-data-server-1.6.1-1.fc5.2.x86_64.rpm 35159546ce167ce80755d53ce1bcefc14a36a70f x86_64/evolution-data-server-devel-1.6.1-1.fc5.2.x86_64.rpm 22dba92f60e7dfa13c2d1ba4db18881a3dadd424 x86_64/debug/evolution-data-server-debuginfo-1.6.1-1.fc5.2.x86_64.rpm d94309cffc37f77ffed31c65ad7149125e391060 i386/evolution-data-server-1.6.1-1.fc5.2.i386.rpm 882c4c3b58fd27e70f9f44417df7ea6d4a6a8570 i386/evolution-data-server-devel-1.6.1-1.fc5.2.i386.rpm 7cffe265c6fa1c011edcbc62500f836cf24b7bc0 i386/debug/evolution-data-server-debuginfo-1.6.1-1.fc5.2.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-640 2005-07-27 ---------------------------------------------------------------------Product : Fedora Core 4 Name : tar Version : 1.15.1 Release : 7.FC4 Summary : A GNU file archiving program. Description : The GNU tar program saves many files together in one archive and can restore individual files (or all of the files) from that archive. Tar can also be used to add supplemental files to an archive and to update or list files in the archive. Tar includes multivolume support, automatic archive compression/decompression, the ability to perform remote archives, and the ability to perform incremental and full backups. If you want to use tar for remote backups, you also need to install the rmt package. ---------------------------------------------------------------------* Wed Jul 27 2005 Peter Vrabec 1.15.1-7.FC4 - exclude listed02.at from testsuite * Wed Jul 27 2005 Peter Vrabec 1.15.1-6.FC4 - A file is dumpable if it is sparse and both --sparse and --totals are specified (#154882) - exclude err.patch, it causes SEGV (#158743) ---------------------------------------------------------------------This update can be downloaded from: e209d298d9939ecd3916eda9eb3af3fd SRPMS/tar-1.15.1-7.FC4.src.rpm 46976c5a9782f2eb0509dcf0785a8651 ppc/tar-1.15.1-7.FC4.ppc.rpm a6eb10ae5fe09dadcfafc40632f40049 ppc/debug/tar-debuginfo-1.15.1-7.FC4.ppc.rpm a4a1bd978adcdb9124afcac655189508 x86_64/tar-1.15.1-7.FC4.x86_64.rpm 36eb52f3d2d36ff0cb6561b1b2169822 x86_64/debug/tar-debuginfo-1.15.1-7.FC4.x86_64.rpm 8bd9a83286de78355961d05c127448e3 i386/tar-1.15.1-7.FC4.i386.rpm 87487946c39654987cf967796d9b167e i386/debug/tar-debuginfo-1.15.1-7.FC4.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.