{"id":45840,"date":"2023-07-28T18:15:04","date_gmt":"2023-07-28T14:15:04","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/173800\/RHSA-2023-4313-01.txt"},"modified":"2023-07-28T23:34:51","modified_gmt":"2023-07-28T19:04:51","slug":"red-hat-security-advisory-2023-4313-01-postgresql","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2023-4313-01-postgresql\/","title":{"rendered":"Red Hat Security Advisory 2023-4313-01 postgresql"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p>=====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p>Synopsis: Moderate: rh-postgresql12-postgresql security update<br \/>\nAdvisory ID: RHSA-2023:4313-01<br \/>\nProduct: Red Hat Software Collections<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2023:4313<br \/>\nIssue date: 2023-07-27<br \/>\nCVE Names: CVE-2023-2454 CVE-2023-2455<br \/>\n=====================================================================<\/p>\n<p>1. Summary:<\/p>\n<p>An update for rh-postgresql12-postgresql is now available for Red Hat<br \/>\nSoftware Collections.<\/p>\n<p>Red Hat Product Security has rated this update as having a security impact<br \/>\nof Moderate. A Common Vulnerability Scoring System (CVSS) base score, which<br \/>\ngives a detailed severity rating, is available for each vulnerability from<br \/>\nthe CVE link(s) in the References section.<\/p>\n<p>2. Relevant releases\/architectures:<\/p>\n<p>Red Hat Software Collections for RHEL Workstation(v. 7) &#8211; ppc64le, s390x, x86_64<br \/>\nRed Hat Software Collections for RHEL(v. 7) &#8211; x86_64<\/p>\n<p>3. Description:<\/p>\n<p>PostgreSQL is an advanced object-relational database management system<br \/>\n(DBMS).<\/p>\n<p>Security Fix(es):<\/p>\n<p>* postgresql: schema_element defeats protective search_path changes<br \/>\n(CVE-2023-2454)<\/p>\n<p>* postgresql: row security policies disregard user ID changes after<br \/>\ninlining. (CVE-2023-2455)<\/p>\n<p>For more details about the security issue(s), including the impact, a CVSS<br \/>\nscore, acknowledgments, and other related information, refer to the CVE<br \/>\npage(s) listed in the References section.<\/p>\n<p>4. Solution:<\/p>\n<p>For details on how to apply this update, which includes the changes<br \/>\ndescribed in this advisory, refer to:<\/p>\n<p>https:\/\/access.redhat.com\/articles\/11258<\/p>\n<p>If the postgresql service is running, it will be automatically restarted<br \/>\nafter installing this update.<\/p>\n<p>5. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p>2207568 &#8211; CVE-2023-2454 postgresql: schema_element defeats protective search_path changes<br \/>\n2207569 &#8211; CVE-2023-2455 postgresql: row security policies disregard user ID changes after inlining.<\/p>\n<p>6. Package List:<\/p>\n<p>Red Hat Software Collections for RHEL Workstation(v. 7):<\/p>\n<p>Source:<br \/>\nrh-postgresql12-postgresql-12.15-1.el7.src.rpm<\/p>\n<p>ppc64le:<br \/>\nrh-postgresql12-postgresql-12.15-1.el7.ppc64le.rpm<br \/>\nrh-postgresql12-postgresql-contrib-12.15-1.el7.ppc64le.rpm<br \/>\nrh-postgresql12-postgresql-contrib-syspaths-12.15-1.el7.ppc64le.rpm<br \/>\nrh-postgresql12-postgresql-debuginfo-12.15-1.el7.ppc64le.rpm<br \/>\nrh-postgresql12-postgresql-devel-12.15-1.el7.ppc64le.rpm<br \/>\nrh-postgresql12-postgresql-docs-12.15-1.el7.ppc64le.rpm<br \/>\nrh-postgresql12-postgresql-libs-12.15-1.el7.ppc64le.rpm<br \/>\nrh-postgresql12-postgresql-plperl-12.15-1.el7.ppc64le.rpm<br \/>\nrh-postgresql12-postgresql-plpython-12.15-1.el7.ppc64le.rpm<br \/>\nrh-postgresql12-postgresql-pltcl-12.15-1.el7.ppc64le.rpm<br \/>\nrh-postgresql12-postgresql-server-12.15-1.el7.ppc64le.rpm<br \/>\nrh-postgresql12-postgresql-server-syspaths-12.15-1.el7.ppc64le.rpm<br \/>\nrh-postgresql12-postgresql-static-12.15-1.el7.ppc64le.rpm<br \/>\nrh-postgresql12-postgresql-syspaths-12.15-1.el7.ppc64le.rpm<br \/>\nrh-postgresql12-postgresql-test-12.15-1.el7.ppc64le.rpm<\/p>\n<p>s390x:<br \/>\nrh-postgresql12-postgresql-12.15-1.el7.s390x.rpm<br \/>\nrh-postgresql12-postgresql-contrib-12.15-1.el7.s390x.rpm<br \/>\nrh-postgresql12-postgresql-contrib-syspaths-12.15-1.el7.s390x.rpm<br \/>\nrh-postgresql12-postgresql-debuginfo-12.15-1.el7.s390x.rpm<br \/>\nrh-postgresql12-postgresql-devel-12.15-1.el7.s390x.rpm<br \/>\nrh-postgresql12-postgresql-docs-12.15-1.el7.s390x.rpm<br \/>\nrh-postgresql12-postgresql-libs-12.15-1.el7.s390x.rpm<br \/>\nrh-postgresql12-postgresql-plperl-12.15-1.el7.s390x.rpm<br \/>\nrh-postgresql12-postgresql-plpython-12.15-1.el7.s390x.rpm<br \/>\nrh-postgresql12-postgresql-pltcl-12.15-1.el7.s390x.rpm<br \/>\nrh-postgresql12-postgresql-server-12.15-1.el7.s390x.rpm<br \/>\nrh-postgresql12-postgresql-server-syspaths-12.15-1.el7.s390x.rpm<br \/>\nrh-postgresql12-postgresql-static-12.15-1.el7.s390x.rpm<br \/>\nrh-postgresql12-postgresql-syspaths-12.15-1.el7.s390x.rpm<br \/>\nrh-postgresql12-postgresql-test-12.15-1.el7.s390x.rpm<\/p>\n<p>x86_64:<br \/>\nrh-postgresql12-postgresql-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-contrib-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-contrib-syspaths-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-debuginfo-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-devel-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-docs-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-libs-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-plperl-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-plpython-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-pltcl-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-server-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-server-syspaths-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-static-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-syspaths-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-test-12.15-1.el7.x86_64.rpm<\/p>\n<p>Red Hat Software Collections for RHEL(v. 7):<\/p>\n<p>Source:<br \/>\nrh-postgresql12-postgresql-12.15-1.el7.src.rpm<\/p>\n<p>x86_64:<br \/>\nrh-postgresql12-postgresql-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-contrib-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-contrib-syspaths-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-debuginfo-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-devel-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-docs-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-libs-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-plperl-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-plpython-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-pltcl-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-server-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-server-syspaths-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-static-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-syspaths-12.15-1.el7.x86_64.rpm<br \/>\nrh-postgresql12-postgresql-test-12.15-1.el7.x86_64.rpm<\/p>\n<p>These packages are GPG signed by Red Hat for security. Our key and<br \/>\ndetails on how to verify the signature are available from<br \/>\nhttps:\/\/access.redhat.com\/security\/team\/key\/<\/p>\n<p>7. References:<\/p>\n<p>https:\/\/access.redhat.com\/security\/cve\/CVE-2023-2454<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2023-2455<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#moderate<\/p>\n<p>8. Contact:<\/p>\n<p>The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p>Copyright 2023 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p>iQIcBAEBCAAGBQJkwn0rAAoJENzjgjWX9erEgzoP\/A7d\/F+IVuddE1o169mZWEfO<br \/>\nkOvEc4bI3fbOJRFjB3SerD6MBMigC9hD3uuuDUG6quvBf9y42WL2CoLhRbhNymTe<br \/>\nwnQCfRhWOZEwEerdDsUg9TpC3q6cOpL4oJBN0fOe\/mA7yzKK6ehWnMW3NW6QmpQE<br \/>\nhSbhJOnU0OF6U8TzlnigP2YGxwuA37AffFSz\/za92OYRZ6znOGXD1Hb03YCB8maI<br \/>\nSHBpf3XQm5BynOStY4DneYz+H4rt\/pMQxuQrj8fJs3shxPexMbdJMxTSkZg4iVcw<br \/>\nxeTZ3hUbh\/IQitjdI5qlmueN4Fg+zxkrcB8iDnyDEpei+4qP392TtEgpOJAv\/OJ2<br \/>\nqb09FrDx49a0D+lBZ6tbQJe\/nO3P3dT\/cbLDtoehLK8h3HTp3QbTGxA\/vvkvaYcA<br \/>\nR4CibfDd3f70VhRAJhQQHeox\/SxQy1qDRkmNFbFtLSj3\/pa2RyBD6Dy7MynfUhku<br \/>\n+YYZRqPQeMBmx7prXAHJqeXFYSwdEuTJZMrdAgqZ7qjgKD+vTq3YhD2plL5loEfh<br \/>\nYelYqcz6nmdB+\/fBW4mfAIf\/+NMrv0LG4ak7CCAGaQt5e6YIHVr+X\/c++zGHvOBo<br \/>\nBZ7DFeOP+nfbDP3rKVAzCVYkLTKBh9WMoepK7zD+H34dxdLOwTWYfzZmB5uDq6js<br \/>\nAZp3FTK9OHiJZokHj+ol<br \/>\n=NiAD<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<br \/>\n&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: rh-postgresql12-postgresql security update Advisory ID: RHSA-2023:4313-01 Product: Red Hat Software Collections Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2023:4313 Issue date: 2023-07-27 CVE Names: CVE-2023-2454 CVE-2023-2455 ===================================================================== 1. Summary: An update for rh-postgresql12-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-45840","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45840","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=45840"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45840\/revisions"}],"predecessor-version":[{"id":45856,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45840\/revisions\/45856"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=45840"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=45840"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=45840"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}