You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa PostgreSQL

Sigurnosni nedostatak programskog paketa PostgreSQL

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-4282-1
February 18, 2020

postgresql-10, postgresql-11 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 19.10
– Ubuntu 18.04 LTS

Summary:

PostgreSQL could allow unintended access to the database.

Software Description:
– postgresql-11: Object-relational SQL database
– postgresql-10: Object-relational SQL database

Details:

It was discovered that PostgreSQL incorrectly performed authorization
checks when handling the “ALTER … DEPENDS ON EXTENSION” sub-commands. A
remote attacker could possibly use this issue to drop any function,
procedure, materialized view, index, or trigger under certain conditions.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.10:
postgresql-11 11.7-0ubuntu0.19.10.1

Ubuntu 18.04 LTS:
postgresql-10 10.12-0ubuntu0.18.04.1

This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart PostgreSQL to
make all the necessary changes.

References:
https://usn.ubuntu.com/4282-1
CVE-2020-1720

Package Information:
https://launchpad.net/ubuntu/+source/postgresql-11/11.7-0ubuntu0.19.10.1
https://launchpad.net/ubuntu/+source/postgresql-10/10.12-0ubuntu0.18.04.1

—–BEGIN PGP SIGNATURE—–

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl5L7pQACgkQZWnYVadE
vpME/w//SHQG9Gc+oOp6q3sW87Ml9zZT/lmJyQk+Q++go8vc2pHTlxeJ9U2u6wlm
jtO796kd8wMF4Y7yuQfp2y8xuKELSuKCGGcExxhgQ6Y/+QWLmJasJ1cAxPB9TRsV
hEk50glx87sj2KQVKQzCaZhr5da2+h8kVgfKz/ejBz3dxU9V2LYzfM7QmEChZj/C
UHs8R5yTN/XC0HR2jPWBbkU1vSS83idQQmFaBO37XJeny3BO2Ap6LAqZKQQ2UqEU
e08NlRqSKhwZgIQDcu8taWAWWIFLaNPscq+bLyVncJm5OGkVDAF7m6ZywT9HtGZx
0EnFD8ZBznnl71q4DoUYMTdwn+m8HzOntB6kOJRrv3Qajxwxe5bp+i/F4xuRAm0o
obIZczP1sh9Klqd+nfz0Sintfp/qHrcUe8Jrc37QBrrfBQyfGksTMOCmiuDBIuzL
mua4mEZ67/F4nHYwZhxCjHwNZbNyl5HRfCMwbGC5T4QmQoDCtTIPTVRBeX0MZcm4
VVwl/cyZe507fiIBfgJO6zZAQOazLabojUFqp+kb/7r3IJfryIjholDmjz2cs6fE
ZqxqxZie6t2xuYaJENpvWFwDQg3Q8M1dGTRwSZHMR703P4CTP+03JuyMe95/HpJA
JiVPq9im2E8/IIIJuP+x/lbtq1C0FaoUVMajyoGh9NoQCxUGzAs=
=nMZU
—–END PGP SIGNATURE—–

AutorJosip Papratovic
Cert idNCERT-REF-2020-02-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa WebKitGTK+

Otkriveni su sigurnosni nedostaci u programskom paketu WebKitGTK+ za operacijski sustav Ubuntu. Otkriveni nedostaci potencijalnim napadačima omogućuju izazivanje DoS stanja,...

Close