Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

postgresql: security update to 11.5 #1953

Closed
4 tasks done
KexyBiscuit opened this issue Aug 9, 2019 · 2 comments
Closed
4 tasks done

postgresql: security update to 11.5 #1953

KexyBiscuit opened this issue Aug 9, 2019 · 2 comments
Assignees
Labels
security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade

Comments

@KexyBiscuit
Copy link
Member

KexyBiscuit commented Aug 9, 2019

CVE IDs: CVE-2019-10208, CVE-2019-10209

Other security advisory IDs: DSA-4493-1, USN-4090-1, ASA-201908-8, MGASA-2019-0225

Descriptions: TYPE in pg_temp executes arbitrary SQL during SECURITY DEFINER execution

Memory disclosure in cross-type comparison for hashed subplan

Patches: N/A

PoC(s): N/A

Architectural progress:

  • AMD64 amd64
  • AArch64 arm64
  • ARMv7 armel
  • PowerPC 64-bit BE ppc64
@KexyBiscuit KexyBiscuit added security Topic/issue involves a security issue/fixed to-stable labels Aug 9, 2019
@KexyBiscuit KexyBiscuit added this to the Summer 2019 milestone Aug 9, 2019
@KexyBiscuit KexyBiscuit self-assigned this Aug 9, 2019
KexyBiscuit added a commit that referenced this issue Aug 9, 2019
@MingcongBai MingcongBai added the upgrade Topic/issue involves a package upgrade label Apr 20, 2020
@MingcongBai
Copy link
Member

All done. @l2dy Please assign an AOSA.

@l2dy
Copy link
Member

l2dy commented Apr 20, 2020

Use AOSA-2020-0049.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade
Projects
None yet
Development

No branches or pull requests

3 participants