Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
Several vulnerabilities have been discovered in the PostgreSQL database system. CVE-2023-5868 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5553-1
Multiple vulnerabilities have been found in PostgreSQL, the worst of which could result in remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202211-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: PostgreSQL: Multiple Vulnerabilities Date: November 19, 2022 Bugs: #793734, #808984, #823125, #865255 ID: 202211-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in PostgreSQL, the worst of which could result in remote code execution. Background ========= PostgreSQL is an open source object-relational database management system. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- dev-db/postgresql < 10.22 > = 10.22:10 < 11.17:11 > = 11.17:11 < 12.12:12 > = 12.12:12 < 13.8:13 > = 13.8:13 < 14.5:14 > = 14.5 Description ========== Multiple vulnerabilities have been discovered in PostgreSQL. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All PostgreSQL 10.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-db/postgresql-10.22:10" All PostgreSQL 11.x users should upgrade to the latest version: # emerge --sync # emerge--ask --oneshot --verbose "> =dev-db/postgresql-11.17:11" All PostgreSQL 12.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-db/postgresql-12.12:12" All PostgreSQL 13.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-db/postgresql-13.8:13" All PostgreSQL 14.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-db/postgresql-14.5:14" References ========= [ 1 ] CVE-2021-3677 https://nvd.nist.gov/vuln/detail/CVE-2021-3677 [ 2 ] CVE-2021-23214 https://nvd.nist.gov/vuln/detail/CVE-2021-23214 [ 3 ] CVE-2021-23222 https://nvd.nist.gov/vuln/detail/CVE-2021-23222 [ 4 ] CVE-2021-32027 https://nvd.nist.gov/vuln/detail/CVE-2021-32027 [ 5 ] CVE-2021-32028 https://nvd.nist.gov/vuln/detail/CVE-2021-32028 [ 6 ] CVE-2022-1552 https://nvd.nist.gov/vuln/detail/CVE-2022-1552 [ 7 ] CVE-2022-2625 https://nvd.nist.gov/vuln/detail/CVE-2022-2625 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202211-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Several security issues were fixed in MySQL.. =========================================================================Ubuntu Security Notice USN-5022-3 October 07, 2021 mysql-5.7 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Several security issues were fixed in MySQL. Software Description: - mysql-5.7: MySQL database Details: USN-5022-1 fixed several vulnerabilities in MySQL. This update provides the corresponding update for Ubuntu 16.04 ESM. Original advisory details: Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to MySQL 5.7.35 on Ubuntu 16.04 ESM. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-35.html https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-26.html https://www.oracle.com/security-alerts/cpujul2021.html Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: mysql-server 5.7.35-0ubuntu0.16.04.1+esm1 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5022-3 https://ubuntu.com/security/notices/USN-5022-1 CVE-2021-2146, CVE-2021-2154, CVE-2021-2162, CVE-2021-2166, CVE-2021-2169, CVE-2021-2171, CVE-2021-2179, CVE-2021-2180, CVE-2021-2194, CVE-2021-2226, CVE-2021-2307, CVE-2021-2342, CVE-2021-2372, CVE-2021-2385, CVE-2021-2389, CVE-2021-2390 . Multiple vulnerabilities addressed in MySQL patch for Ubuntu 16.04 ESM on Oct 07, 2021, as outlined in advisory USN-5022-3.. MySQL Update, Ubuntu Security,Database Issues, Software Advisory. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in MySQL.. =========================================================================Ubuntu Security Notice USN-4952-1 May 12, 2021 mysql-5.7, mysql-8.0 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.04 - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in MySQL. Software Description: - mysql-8.0: MySQL database - mysql-5.7: MySQL database Details: Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 8.0.25 in Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. Ubuntu 18.04 LTS has been updated to MySQL 5.7.34. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-34.html https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-24.html https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-25.html https://www.oracle.com/security-alerts/cpuapr2021.html Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.04: mysql-server-8.0 8.0.25-0ubuntu0.21.04.1 Ubuntu 20.10: mysql-server-8.0 8.0.25-0ubuntu0.20.10.1 Ubuntu 20.04 LTS: mysql-server-8.0 8.0.25-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: mysql-server-5.7 5.7.34-0ubuntu0.18.04.1 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4952-1 CVE-2021-2146, CVE-2021-2154, CVE-2021-2162, CVE-2021-2164, CVE-2021-2166, CVE-2021-2169, CVE-2021-2170,CVE-2021-2171, CVE-2021-2172, CVE-2021-2179, CVE-2021-2180, CVE-2021-2193, CVE-2021-2194, CVE-2021-2196, CVE-2021-2201, CVE-2021-2203, CVE-2021-2208, CVE-2021-2212, CVE-2021-2215, CVE-2021-2217, CVE-2021-2226, CVE-2021-2230, CVE-2021-2232, CVE-2021-2278, CVE-2021-2293, CVE-2021-2298, CVE-2021-2299, CVE-2021-2300, CVE-2021-2301, CVE-2021-2304, CVE-2021-2305, CVE-2021-2307, CVE-2021-2308 Package Information: https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.25-0ubuntu0.21.04.1 https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.25-0ubuntu0.20.10.1 https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.25-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.34-0ubuntu0.18.04.1 . Regularly applying security patches for PostgreSQL in Debian systems is crucial for ensuring system stability and database efficiency.. MySQL Update, Database Security, Linux Bug Fixes. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in MySQL.. =========================================================================Ubuntu Security Notice USN-3174-1 January 19, 2017 mysql-5.5, mysql-5.7 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Several security issues were fixed in MySQL. Software Description: - mysql-5.7: MySQL database - mysql-5.5: MySQL database Details: Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 5.5.54 in Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. Ubuntu 16.04 LTS and Ubuntu 16.10 have been updated to MySQL 5.7.17. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: http://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-17.html https://www.oracle.com/security-alerts/cpujan2017.html Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.10: mysql-server-5.7 5.7.17-0ubuntu0.16.10.1 Ubuntu 16.04 LTS: mysql-server-5.7 5.7.17-0ubuntu0.16.04.1 Ubuntu 14.04 LTS: mysql-server-5.5 5.5.54-0ubuntu0.14.04.1 Ubuntu 12.04 LTS: mysql-server-5.5 5.5.54-0ubuntu0.12.04.1 In general, a standard system update will make all the necessary changes. References: CVE-2016-8318, CVE-2016-8327, CVE-2017-3238, CVE-2017-3243, CVE-2017-3244, CVE-2017-3251, CVE-2017-3256, CVE-2017-3258, CVE-2017-3265, CVE-2017-3273, CVE-2017-3291, CVE-2017-3312, CVE-2017-3313, CVE-2017-3317, CVE-2017-3318, CVE-2017-3319, CVE-2017-3320 Package Information: https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.10.1 https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1 https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1 https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.12.04.1 . Several problems addressed in MySQL for Ubuntu versions 16.10, 16.04, 14.04, and 12.04, with crucial patches detailed for every iteration.. MySQL Security Issues, Ubuntu Updates, Database Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Security fix for CVE-2016-9036, CVE-2016-9037. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-badd014afe 2016-12-22 02:23:18.167589 -------------------------------------------------------------------------------- Name : tarantool Product : Fedora 24 Version : 1.6.9.52 Release : 1.fc24 URL : https://www.tarantool.io/en/developers/ Summary : In-memory database and Lua application server Description : Tarantool is a high performance in-memory NoSQL database and Lua application server. Tarantool supports replication, online backup and stored procedures in Lua. This package provides the server daemon and admin tools. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-9036, CVE-2016-9037 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1406682 - CVE-2016-9036 CVE-2016-9037 tarantool: Multiple DoS vulnerabilities [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1406682 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade tarantool' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.41. Please see the MySQL 5.5 Release Notes and Oracle's Critical Patch Update advisory for further details: . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3135-1
Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.40. Please see the MySQL 5.5 Release Notes and Oracle's Critical Patch Update advisory for further details: . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3054-1
Get the latest Linux and open source security news straight to your inbox.