[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 3600-1] postgresql-11 security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -----------------------------------------------------------------------
Debian LTS Advisory DLA-3600-1              debian-lts@lists.debian.org
https://www.debian.org/lts/security/                      Utkarsh Gupta
October 04, 2023                            https://wiki.debian.org/LTS
- -----------------------------------------------------------------------

Package        : postgresql-11
Version        : 11.21-0+deb10u2
CVE ID         : CVE-2023-39417

A SQL Injection vulnerability was found in PostgreSQL, an
object-relational SQL database management system.

An extension script is vulnerable if it uses @extowner@, @extschema@,
or @extschema:...@ inside a quoting construct (dollar quoting, '', or
"").

For Debian 10 buster, this problem has been fixed in version
11.21-0+deb10u2.

We recommend that you upgrade your postgresql-11 packages.

For the detailed security status of postgresql-11 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/postgresql-11

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmUcjhIACgkQgj6WdgbD
S5bM1w/+Nkte5MeS+uFnv9dUjAu2SGeb/UQZ4S+LdE8tvGwu3ab0G6f5j8+00arx
FI5YO+/4UAVHCm9UjyCDUieEA9dK0uQPsz0Yw9q6YzM6QCXdbBw/DY3RoGSW20BB
c35kdPCMipxH/Byp53u2CjeMEe2DBh3qqIWD7n1BS+5umaq561iv3K+ZP/VWAQs6
yoVhMkEgH4aW4estrsPlioJyii7hovnDUoxQIRFCU6d8SZbyHGStb81b6ZySv5aR
w7DZTvM9lg28l91uM3tat2aK1nCQkkhOPIaPbFGR4l47eQUbtmUqyZy9MOU/iLLq
JuuoMKTp7630ZYffoPdjOPcvSX5KDmoVd7j5G0ClPUV3Oz/uuXrqW+NagQ0R2cXZ
hFYUG61Y+FL3N6Nmz9poBdZ0wslTnmZpardsUOOTtlFCGo5SYXdR/VaAWeqQq9DG
dtlzjBHaoAIZivn/KJ2GXCVp3L5peNe4KwZ6nAetEkQP4knTDRA5Bgu/wQ1gFz+L
bLCuRW7YURZMU/5YtvQEIbFKlrigpxxbmIaqekSvLp+R4jpq9YI1UxqqPoU79Ooy
Sqopo6x3aBC5300RRgpD3FDLy3RfDqzwYt1+770NzR7e9S7sP2t6JYkSzi3wMpf3
gtYvty60Hj7Q8PvWeG323DW69+xCeBirHsr67p7/coMWFk+6Cb0=
=Cstz
-----END PGP SIGNATURE-----


Reply to: