VYPR

rpm package

suse/postgresql&distro=SUSE Linux Enterprise Server 12 SP2-LTSS

pkg:rpm/suse/postgresql&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSS

Vulnerabilities (3)

  • CVE-2020-25696HigNov 23, 2020
    affected < 13-4.7.1fixed 13-4.7.1

    A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code

  • CVE-2020-25695HigNov 16, 2020
    affected < 13-4.7.1fixed 13-4.7.1

    A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuse

  • CVE-2020-25694HigNov 16, 2020
    affected < 13-4.7.1fixed 13-4.7.1

    A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic connection parameters while dropping security-relevant paramet