MGASA-2019-0225

Source
https://advisories.mageia.org/MGASA-2019-0225.html
Import Source
https://advisories.mageia.org/MGASA-2019-0225.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0225
Related
Published
2019-08-18T12:39:41Z
Modified
2019-08-18T11:53:26Z
Summary
Updated postgresql packages fix security vulnerabilities
Details

Updated postgresql packages fix security vulnerabilities:

Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function call having inexact argument type match. For example, length('foo'::varchar) and length('foo') are inexact, while length('foo'::text) is exact (CVE-2019-10208).

In a database containing hypothetical, user-defined hash equality operators, an attacker could read arbitrary bytes of server memory. For an attack to become possible, a superuser would need to create unusual operators. It is possible for operators not purpose-crafted for attack to have the properties that enable an attack, but we are not aware of specific examples (CVE-2019-10209).

This update also fixes over 40 bugs that were reported in the last several months. See the upstream release notes for details.

References
Credits

Affected packages

Mageia:7 / postgresql9.6

Package

Name
postgresql9.6
Purl
pkg:rpm/mageia/postgresql9.6?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.6.15-1.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:7 / postgresql11

Package

Name
postgresql11
Purl
pkg:rpm/mageia/postgresql11?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
11.5-1.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / postgresql9.4

Package

Name
postgresql9.4
Purl
pkg:rpm/mageia/postgresql9.4?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.4.24-1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / postgresql9.6

Package

Name
postgresql9.6
Purl
pkg:rpm/mageia/postgresql9.6?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.6.15-1.mga6

Ecosystem specific

{
    "section": "core"
}