Debian alert DLA-2922-1 (pgbouncer)
| From: | Emilio Pozuelo Monfort <pochu@debian.org> | |
| To: | <debian-lts-announce@lists.debian.org> | |
| Subject: | [SECURITY] [DLA 2922-1] pgbouncer security update | |
| Date: | Mon, 14 Feb 2022 13:55:33 +0100 | |
| Message-ID: | <20220214125533.5F9FE2A0AF9@andromeda> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2922-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Emilio Pozuelo Monfort February 14, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : pgbouncer Version : 1.7.2-2+deb9u1 CVE ID : CVE-2021-3935 It was found that PgBouncer, a PostgreSQL connection pooler, was susceptible to an arbitrary SQL injection attack if a man-in-the-middle could inject data when a connection using certificate authentication is established. For Debian 9 stretch, this problem has been fixed in version 1.7.2-2+deb9u1. We recommend that you upgrade your pgbouncer packages. For the detailed security status of pgbouncer please refer to its security tracker page at: https://security-tracker.debian.org/tracker/pgbouncer Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAmIKUUIACgkQnUbEiOQ2 gwKo7BAAowBVnGuvAH+jt5DeljGhW1Rma/3gcIe9aKm79L4jv4itK+10lRi6LEeV ecKSRW38EgQroEQFro5OYo8ojjWQV8WZ5Q+vI7Xb+t3C3LYmfzBoM+2i9yRoRTmM JAmBJczx8QZ8Sdjh1AXWauFjUv25g09pGbqmaTQYSZ3OZMnj6cdkNdGgDVLyjSQf 5C+3YA9n8IsyhbpqFCZA4jl5N9dKHJaNCzcIer0MB3Ayb/HvBvSoM2ushfGcu/qL 2XT7zAobiJt5WFed3BOZCavzdQYVMmTMtYIKvb8ZRtHJrUMVGdLgFCzRPhDr1m7T 2SxVhwvybKMNtOydMSiXCkdMyztEXDsLDatdigeHcOtecwCct7lwdluRVhlT9IFp 7swyW49TvJvbDXOmU4ca/rOxfTGFYs7trJOprS/tUpL79Ta4dTdnXQp2Kl8JEKCO l35oMfNpIFALCGiEo3tm8cAlg0Ur6WcWVQ8zL44WSqPg0KlFVYxUS0QIWG5ZmYso F/1BzPA8mJNqFLFIdaxm0RKLYXgkDzPj2PLvxHa6DYbzn0VBXWrolbzibto2XWVJ a0MI89pkwSYqjTG0QzWUMF24Y2p17IeTnmlh9BfdPQJ3q1/hsuQdrFCIKDx7hzPB 4FbzKa2Ke/gtyI0W+aqp1lKqgz9zTcbPKC85fkvgvMbspw9nDzg= =4aHp -----END PGP SIGNATURE-----
