MGASA-2021-0121
Dashboard / Vulnerabilities / MGASA-2021-0121
MGASA-2021-0121
Summary: Updated postgresql packages fix security vulnerabilities
Details: A user having an UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may be able to acquire denied-column values from an error message (CVE-2021-3393). A user having a SELECT privilege on an individual column can craft a special query that returns all columns of the table. Additionally, a stored view that uses column-level privileges will have incomplete column-usage bitmaps. In installations that depend on column-level permissions for security, it is recommended to execute CREATE OR REPLACE on all user-defined views to force them to be re-parsed (CVE-2021-20229). PostgreSQL 11 was only affected by CVE-2021-3393 and both PostgreSQL 11 and 13 were affected by CVE-2021-20229. PostgreSQL 9.6 was updated to fix bugs.
References: https://advisories.mageia.org/MGASA-2021-0121.html, https://bugs.mageia.org/show_bug.cgi?id=28373, https://www.postgresql.org/about/news/postgresql-132-126-1111-1016-9621-and-9525-released-2165/
Affected packages
Package
Name: postgresql9.6
Purl: pkg:rpm/mageia/postgresql9.6?arch=source&distro=mageia-7
Affected ranges
Type: ECOSYSTEM
Events:
