|
|
Subscribe / Log in / New account

Debian alert DLA-2922-1 (pgbouncer)

From:  Emilio Pozuelo Monfort <pochu@debian.org>
To:  <debian-lts-announce@lists.debian.org>
Subject:  [SECURITY] [DLA 2922-1] pgbouncer security update
Date:  Mon, 14 Feb 2022 13:55:33 +0100
Message-ID:  <20220214125533.5F9FE2A0AF9@andromeda>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2922-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Emilio Pozuelo Monfort February 14, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : pgbouncer Version : 1.7.2-2+deb9u1 CVE ID : CVE-2021-3935 It was found that PgBouncer, a PostgreSQL connection pooler, was susceptible to an arbitrary SQL injection attack if a man-in-the-middle could inject data when a connection using certificate authentication is established. For Debian 9 stretch, this problem has been fixed in version 1.7.2-2+deb9u1. We recommend that you upgrade your pgbouncer packages. For the detailed security status of pgbouncer please refer to its security tracker page at: https://security-tracker.debian.org/tracker/pgbouncer Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAmIKUUIACgkQnUbEiOQ2 gwKo7BAAowBVnGuvAH+jt5DeljGhW1Rma/3gcIe9aKm79L4jv4itK+10lRi6LEeV ecKSRW38EgQroEQFro5OYo8ojjWQV8WZ5Q+vI7Xb+t3C3LYmfzBoM+2i9yRoRTmM JAmBJczx8QZ8Sdjh1AXWauFjUv25g09pGbqmaTQYSZ3OZMnj6cdkNdGgDVLyjSQf 5C+3YA9n8IsyhbpqFCZA4jl5N9dKHJaNCzcIer0MB3Ayb/HvBvSoM2ushfGcu/qL 2XT7zAobiJt5WFed3BOZCavzdQYVMmTMtYIKvb8ZRtHJrUMVGdLgFCzRPhDr1m7T 2SxVhwvybKMNtOydMSiXCkdMyztEXDsLDatdigeHcOtecwCct7lwdluRVhlT9IFp 7swyW49TvJvbDXOmU4ca/rOxfTGFYs7trJOprS/tUpL79Ta4dTdnXQp2Kl8JEKCO l35oMfNpIFALCGiEo3tm8cAlg0Ur6WcWVQ8zL44WSqPg0KlFVYxUS0QIWG5ZmYso F/1BzPA8mJNqFLFIdaxm0RKLYXgkDzPj2PLvxHa6DYbzn0VBXWrolbzibto2XWVJ a0MI89pkwSYqjTG0QzWUMF24Y2p17IeTnmlh9BfdPQJ3q1/hsuQdrFCIKDx7hzPB 4FbzKa2Ke/gtyI0W+aqp1lKqgz9zTcbPKC85fkvgvMbspw9nDzg= =4aHp -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds