|
|
Log in / Subscribe / Register

Mageia alert MGASA-2021-0121 (postgresql)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2021-0121: Updated postgresql packages fix security vulnerabilities
Date:  Fri, 12 Mar 2021 02:26:56 +0100
Message-ID:  <20210312012656.8C2C69F993@duvel.mageia.org>
Archive-link:  Article

MGASA-2021-0121 - Updated postgresql packages fix security vulnerabilities Publication date: 12 Mar 2021 URL: https://advisories.mageia.org/MGASA-2021-0121.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-3393, CVE-2021-20229 Description: A user having an UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may be able to acquire denied-column values from an error message (CVE-2021-3393). A user having a SELECT privilege on an individual column can craft a special query that returns all columns of the table. Additionally, a stored view that uses column-level privileges will have incomplete column-usage bitmaps. In installations that depend on column-level permissions for security, it is recommended to execute CREATE OR REPLACE on all user-defined views to force them to be re-parsed (CVE-2021-20229). PostgreSQL 11 was only affected by CVE-2021-3393 and both PostgreSQL 11 and 13 were affected by CVE-2021-20229. PostgreSQL 9.6 was updated to fix bugs. References: - https://bugs.mageia.org/show_bug.cgi?id=28373 - https://www.postgresql.org/about/news/postgresql-132-126-... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3393 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-2... SRPMS: - 7/core/postgresql9.6-9.6.21-1.mga7 - 7/core/postgresql11-11.11-1.mga7 - 8/core/postgresql11-11.11-1.mga8 - 8/core/postgresql13-13.2-1.mga8


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds