A user having an UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may be able to acquire denied-column values from an error message (CVE-2021-3393). A user having a SELECT privilege on an individual column can craft a special . MGASA-2021-0121 - Updated postgresql packages fix security vulnerabilities Publication date: 12 Mar 2021 URL: https://advisories.mageia.org/MGASA-2021-0121.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-3393, CVE-2021-20229 A user having an UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may be able to acquire denied-column values from an error message (CVE-2021-3393). A user having a SELECT privilege on an individual column can craft a special query that returns all columns of the table. Additionally, a stored view that uses column-level privileges will have incomplete column-usage bitmaps. In installations that depend on column-level permissions for security, it is recommended to execute CREATE OR REPLACE on all user-defined views to force them to be re-parsed (CVE-2021-20229). PostgreSQL 11 was only affected by CVE-2021-3393 and both PostgreSQL 11 and 13 were affected by CVE-2021-20229. PostgreSQL 9.6 was updated to fix bugs. References: - https://bugs.mageia.org/show_bug.cgi?id=28373 - https:// - https://www.cve.org/CVERecord?id=CVE-2021-3393 - https://www.cve.org/CVERecord?id=CVE-2021-20229 SRPMS: - 7/core/postgresql9.6-9.6.21-1.mga7 - 7/core/postgresql11-11.11-1.mga7 - 8/core/postgresql11-11.11-1.mga8 - 8/core/postgresql13-13.2-1.mga8 . Mageia 2021-0121 enhances security by updating postgresql packages to address vulnerabilities that affect both security protocols and access restrictions.. Postgresql Update, Security Advisory, Mageia 2021, Access Control Issues. . LinuxSecurity.com Team
Updated j2sdk fixes so many bugs we just couldn't ignore it . Date: Thu, 13 Jul 2006 11:45:31 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: ERRATA for "java" on SL 301,302,303,304,305,307 i386,x86_64 now available Comments: To:
Get the latest Linux and open source security news straight to your inbox.