postgresql-12 12.4-1 source package in Ubuntu
Changelog
postgresql-12 (12.4-1) unstable; urgency=medium * New upstream version. + Set a secure search_path in logical replication walsenders and apply workers (Noah Misch) A malicious user of either the publisher or subscriber database could potentially cause execution of arbitrary SQL code by the role running replication, which is often a superuser. Some of the risks here are equivalent to those described in CVE-2018-1058, and are mitigated in this patch by ensuring that the replication sender and receiver execute with empty search_path settings. (As with CVE-2018-1058, that change might cause problems for under-qualified names used in replicated tables' DDL.) Other risks are inherent in replicating objects that belong to untrusted roles; the most we can do is document that there is a hazard to consider. (CVE-2020-14349) + Make contrib modules' installation scripts more secure (Tom Lane) Attacks similar to those described in CVE-2018-1058 could be carried out against an extension installation script, if the attacker can create objects in either the extension's target schema or the schema of some prerequisite extension. Since extensions often require superuser privilege to install, this can open a path to obtaining superuser privilege. To mitigate this risk, be more careful about the search_path used to run an installation script; disable check_function_bodies within the script; and fix catalog-adjustment queries used in some contrib modules to ensure they are secure. Also provide documentation to help third-party extension authors make their installation scripts secure. This is not a complete solution; extensions that depend on other extensions can still be at risk if installed carelessly. (CVE-2020-14350) * DH 13. -- Christoph Berg <email address hidden> Tue, 11 Aug 2020 12:07:26 +0200
Upload details
- Uploaded by:
- Debian PostgreSQL Maintainers
- Uploaded to:
- Sid
- Original maintainer:
- Debian PostgreSQL Maintainers
- Architectures:
- any all
- Section:
- misc
- Urgency:
- Medium Urgency
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
postgresql-12_12.4-1.dsc | 3.5 KiB | 483e2c17b982240256bdd5812b3ed0669c5017e4be645423e0bbb409fb759d6f |
postgresql-12_12.4.orig.tar.bz2 | 19.7 MiB | bee93fbe2c32f59419cb162bcc0145c58da9a8644ee154a30b9a5ce47de606cc |
postgresql-12_12.4-1.debian.tar.xz | 23.2 KiB | 525e1a0bc8f14cf5a437f1c8775be501c6490f8c55a45d9b87f905cfd6d5c87b |
Available diffs
No changes file available.
Binary packages built by this source
- libecpg-compat3: No summary available for libecpg-compat3 in ubuntu groovy.
No description available for libecpg-compat3 in ubuntu groovy.
- libecpg-compat3-dbgsym: No summary available for libecpg-compat3-dbgsym in ubuntu groovy.
No description available for libecpg-
compat3- dbgsym in ubuntu groovy.
- libecpg-dev: No summary available for libecpg-dev in ubuntu groovy.
No description available for libecpg-dev in ubuntu groovy.
- libecpg-dev-dbgsym: No summary available for libecpg-dev-dbgsym in ubuntu groovy.
No description available for libecpg-dev-dbgsym in ubuntu groovy.
- libecpg6: No summary available for libecpg6 in ubuntu groovy.
No description available for libecpg6 in ubuntu groovy.
- libecpg6-dbgsym: No summary available for libecpg6-dbgsym in ubuntu hirsute.
No description available for libecpg6-dbgsym in ubuntu hirsute.
- libpgtypes3: No summary available for libpgtypes3 in ubuntu groovy.
No description available for libpgtypes3 in ubuntu groovy.
- libpgtypes3-dbgsym: No summary available for libpgtypes3-dbgsym in ubuntu groovy.
No description available for libpgtypes3-dbgsym in ubuntu groovy.
- libpq-dev: No summary available for libpq-dev in ubuntu groovy.
No description available for libpq-dev in ubuntu groovy.
- libpq5: No summary available for libpq5 in ubuntu groovy.
No description available for libpq5 in ubuntu groovy.
- libpq5-dbgsym: No summary available for libpq5-dbgsym in ubuntu groovy.
No description available for libpq5-dbgsym in ubuntu groovy.
- postgresql-12: No summary available for postgresql-12 in ubuntu groovy.
No description available for postgresql-12 in ubuntu groovy.
- postgresql-12-dbgsym: No summary available for postgresql-12-dbgsym in ubuntu groovy.
No description available for postgresql-
12-dbgsym in ubuntu groovy.
- postgresql-client-12: No summary available for postgresql-client-12 in ubuntu groovy.
No description available for postgresql-
client- 12 in ubuntu groovy.
- postgresql-client-12-dbgsym: No summary available for postgresql-client-12-dbgsym in ubuntu hirsute.
No description available for postgresql-
client- 12-dbgsym in ubuntu hirsute.
- postgresql-doc-12: No summary available for postgresql-doc-12 in ubuntu groovy.
No description available for postgresql-doc-12 in ubuntu groovy.
- postgresql-plperl-12: No summary available for postgresql-plperl-12 in ubuntu hirsute.
No description available for postgresql-
plperl- 12 in ubuntu hirsute.
- postgresql-plperl-12-dbgsym: No summary available for postgresql-plperl-12-dbgsym in ubuntu groovy.
No description available for postgresql-
plperl- 12-dbgsym in ubuntu groovy.
- postgresql-plpython3-12: No summary available for postgresql-plpython3-12 in ubuntu groovy.
No description available for postgresql-
plpython3- 12 in ubuntu groovy.
- postgresql-plpython3-12-dbgsym: No summary available for postgresql-plpython3-12-dbgsym in ubuntu groovy.
No description available for postgresql-
plpython3- 12-dbgsym in ubuntu groovy.
- postgresql-pltcl-12: No summary available for postgresql-pltcl-12 in ubuntu hirsute.
No description available for postgresql-pltcl-12 in ubuntu hirsute.
- postgresql-pltcl-12-dbgsym: No summary available for postgresql-pltcl-12-dbgsym in ubuntu groovy.
No description available for postgresql-
pltcl-12- dbgsym in ubuntu groovy.
- postgresql-server-dev-12: No summary available for postgresql-server-dev-12 in ubuntu groovy.
No description available for postgresql-
server- dev-12 in ubuntu groovy.