Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5401-1] postgresql-13 security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5401-1] postgresql-13 security update


Chronologisch Thread  
  • From: Moritz Muehlenhoff <jmm AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5401-1] postgresql-13 security update
  • Date: Thu, 11 May 2023 16:36:32 +0000
  • Authentication-results: mail.piratenpartei.de; dkim=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 2001:41b8:202:deb:216:36ff:fe40:4002) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
  • List-archive: https://lists.debian.org/msgid-search/ZF0ZkFIzcPUiyaeh AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=zWnVNXOhuiSYdjqj04jf9kpl28gWFjxkutQbe3zxGLU=; b=Z8 a+G5t1BXwiMbELhbMjvSJJkOi8lUY993s1/jvb3KL9GyreTJGytK4SctazTRre25nkh1CThbCPsHv wC9THBY36N0ub/78+QGJi5BfnxQLGgjVFW7Yv1E5n7OxzbD+F8rhkaO+EP9ciOl07BehTFGVX/jAm TeSNh8uIqjfpGm/4VFwvmtpPG7MxWBWsZ1WIMZaj3vEhvXfGzKKcjlz9R7ffuXc8sQe8DLtP71J8O 0fAHtFEZo07PeVlBTkMrIn1xF4TxIISTm2DDbqlpvBM/Hjf9NYuDSwSqeCWgCa0/ZZrG+VctwX0v3 WVxuxu/fDunXW9fOMHdIOSjdrmzdMJXA==;
  • Old-return-path: <jmm AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Thu, 11 May 2023 16:36:58 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <9cXWBCVXuZN.A.R6E.qmRXkB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5401-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
May 11, 2023 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : postgresql-13
CVE ID : CVE-2023-2454 CVE-2023-2455

Two security issues were found in PostgreSQL, which may result in
privilege escalation or incorrect policy enforcement.

For the stable distribution (bullseye), these problems have been fixed in
version 13.11-0+deb11u1.

We recommend that you upgrade your postgresql-13 packages.

For the detailed security status of postgresql-13 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/postgresql-13

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmRdF+kACgkQEMKTtsN8
TjZnMA/+OW6jZvbc8StDbvz+I23baEoZizDuXYQ+LxMTBlXQMU52AsZqOOVNHWkc
wWG2DtZRNWVPUftfJORenpjDMviqR+/yBJLlOu4jH68V8EFtv1I9jk70AmOGccL4
mYSr66iawcIpzQFo5mv/BcMREI5raSNT/tFDtIBRfQlEYMwLfnBfprN/DGzn5x/p
4Wn/7AH7a0Gu2S69YaEpgMo4eJ3g9wEsG8wgDNUieNXT67BH2qRt0h/9My2bsNVv
/b0XkX+0wlDEOAd9TJSTcSqOXIlJ/8UV9DPlZE202RzrFrrcYuIyJUxdKyBDHnOT
W/uWkNBTjUcE72RsSmN8XtygUA/YJIk8jtbTLSysyoSb0ONNbKo74HCwKOLTzyoR
84SEd5IknZRWfmszL0wZj8qy3YWrPes2mqfFQYWXGPrjPFJmkksWU0fmuLD8rt7L
02XSPoWbM47FNA+12lKqFEb39woCxo/D46G2QX0c6gIm9oeyYg1WUApmVBqRkDsp
s/Fv1kBeyTzq7MGUEWjpNiJaHSna3j893kr7cfnTcBe5OgKe/7yijVIf7bSoGmcv
Lvlb6zqQ7K5V/Mv8he9k6eInvpiIzEDTCL+BI3tXde3BO/TMTFgpgSXOAizIB+PX
Vz6TzW07blMzNxhKl6YqVpWt7tMtRefLdzg4CMA3QMrvzv8zPXU=
=D+6d
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5401-1] postgresql-13 security update, Moritz Muehlenhoff, 11.05.2023

Archiv bereitgestellt durch MHonArc 2.6.24.

Seitenanfang