Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5135-1] postgresql-11 security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5135-1] postgresql-11 security update


Chronologisch Thread 
  • From: Moritz Muehlenhoff <jmm AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5135-1] postgresql-11 security update
  • Date: Thu, 12 May 2022 19:28:08 +0000
  • List-archive: https://lists.debian.org/msgid-search/20220512192808.GA18556 AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From: Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=cLH5Marv1LzqO2c3oBpJJuWfdfumF28wOUrKNAMefV8=; b=TT RQpFSPVeC+4Ix3xjBqLij+rVY6TENXCgXBC/F/yJ77Nw3Txy4Verxu4ydUxzV8gilQFXhZApBNwOR s1+dP8BxmrZnPPBxdj2cgH/Klb+Lg9bGRbqUi0Bp/uf97R8XQBKabEb+TDnpsEyJiRQaHETpY/RK8 iev6yBUaR5ERm1Znp8GdahfXDE3alM4IOr2Hqrh/GZoro9Ls7D0XsvhJmVrFrXyaikiscB6yOztQz tB/wzsrDGkPEv6X7BsYH+5LCpw4cUOOtLkan4dWR2P97WFDHi7XyVa1SQTuAO+B9W2wT7pslK9mh1 Tq69EPYgj0wA6UBQmVFuGOucOq1ft2aw==;
  • Old-return-path: <jmm AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Thu, 12 May 2022 19:28:28 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <363QFKydAjN.A.pQH.c_VfiB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5135-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
May 12, 2022 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : postgresql-11
CVE ID : CVE-2022-1552

Alexander Lakhin discovered that the autovacuum feature and multiple
commands could escape the "security-restricted operation" sandbox.

For additional information please refer to the upstream announcement
at https://www.postgresql.org/support/security/CVE-2022-1552/

For the oldstable distribution (buster), this problem has been fixed
in version 11.16-0+deb10u1.

We recommend that you upgrade your postgresql-11 packages.

For the detailed security status of postgresql-11 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/postgresql-11

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmJ9XysACgkQEMKTtsN8
TjaHVBAAj18AwRwQOHa0Yym85RlQWTcQVWD7oZIUGP/SSSaBf4fpDJXAK8zQpf6s
HjyEnYUJsuUPJo+QkltV0d43RN/KFWivFJOKpdr6RaVDL2n/B6wpKFo4BpBDby/6
4YBdYdOVTqfv9pNF6SbjTQWF2MVpsYX3PP0fJb3TGzHsdeNeE3+4Wk76gSBehVeR
Peq9AnL9FpwuLra3Hu6Gy5iPmVbkFZUkkeVE1SqwmX97xPxinm+v0b/xLhClM3du
4pX/BDsKp8ze87cYyFLfryWg6IBjpj9Nu/hIadl4jNdq4iGbHwmZFZ62sHeln/qQ
taLZzgmf8/Bni5I5+LpNMJdVWOTk0amWUXA/sgBnjwGuWynV5mKUAUDBDeJfIyaY
fg4+9lGOG3etaaA+VDEBg7wW8TwdoGfuOaM6eLgWc7qLudJoZrVSDHGaEa42Xcsr
F+/pI5cia7jieKQmZsk2tbBN4hjTmisgqX2wD+wsTzXeZBbmaDOPYVyRBKgUU6w8
SP5bY6Mct7qu3ICafPv//clftsVhqWCHaZScl64wC8zujpT+HHHWPLntlttnB++s
wvLpV1EPrVaBgHABKN/84Xchy4L1XFoUgVdPJCSKy6TDwnmneeiFRnphT/l0Ab1E
JOp78KkMq3Qmk0KhpHSi+tbt3PqAOBjidAYztnhku7dgqE/v6q0=
=WmUR
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5135-1] postgresql-11 security update, Moritz Muehlenhoff, 12.05.2022

Archiv bereitgestellt durch MHonArc 2.6.24.

Seitenanfang