Ubuntu Security Update USN-4633-1: PostgreSQL vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,910
Reaction score
75
Credits
-1,257
Peter Eisentraut discovered that PostgreSQL incorrectly handled connection security settings. Client applications could possibly be connecting with certain security parameters dropped, contrary to expectations. (CVE-2020-25694) Etienne Stalmans discovered that PostgreSQL incorrectly handled the security restricted operation sandbox. An authenticated remote attacker could possibly use this issue to execute arbitrary SQL functions as a superuser. (CVE-2020-25695) Nick Cleaton discovered that PostgreSQL incorrectly handled the \gset meta-command. A remote attacker with a compromised server could possibly use this issue to execute arbitrary code. (CVE-2020-25696)

Continue reading...
 


Follow Linux.org

Staff online

Members online


Latest posts

Top