VYPR

rpm package

almalinux/postgresql-private-devel

pkg:rpm/almalinux/postgresql-private-devel

Vulnerabilities (29)

  • CVE-2023-5870LowDec 10, 2023
    affected < 13.13-1.el9_3fixed 13.13-1.el9_3

    A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background

  • CVE-2023-5869HigDec 10, 2023
    affected < 13.13-1.el9_3fixed 13.13-1.el9_3

    A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overfl

  • CVE-2023-5868MedDec 10, 2023
    affected < 13.13-1.el9_3fixed 13.13-1.el9_3

    A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclo

  • CVE-2023-39418LowAug 11, 2023
    affected < 15.5-1.module_el9.3.0+52+21733919fixed 15.5-1.module_el9.3.0+52+21733919

    A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.

  • CVE-2023-39417HigAug 11, 2023
    affected < 13.13-1.el9_3fixed 13.13-1.el9_3

    IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, a

  • CVE-2023-2455MedJun 9, 2023
    affected < 13.11-1.el9_2fixed 13.11-1.el9_2

    Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happe

  • CVE-2023-2454HigJun 9, 2023
    affected < 13.11-1.el9_2fixed 13.11-1.el9_2

    schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.

  • CVE-2022-41862LowMar 3, 2023
    affected < 13.10-1.el9_1fixed 13.10-1.el9_1

    In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.

  • CVE-2022-2625HigAug 18, 2022
    affected < 13.10-1.el9_1fixed 13.10-1.el9_1

    A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim

Page 2 of 2