UBUNTU-CVE-2022-1552
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-1552
UBUNTU-CVE-2022-1552
Summary:
Details: A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and pg_amcheck commands activated relevant protections too late or not at all during the process. This flaw allows an attacker with permission to create non-temporary objects in at least one schema to execute arbitrary SQL functions under a superuser identity.
References: https://ubuntu.com/security/CVE-2022-1552, https://www.postgresql.org/about/news/postgresql-143-137-1211-1116-and-1021-released-2449/, https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=ab49ce7c3414ac19e4afb386d7843ce2d2fb8bda, https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=677a494789062ca88e0142a17bedd5415f6ab0aa, https://ubuntu.com/security/notices/USN-5440-1, https://ubuntu.com/security/notices/USN-5676-1, https://www.cve.org/CVERecord?id=CVE-2022-1552
Affected packages
Package
Name: postgresql-9.3
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-infra-legacy/trusty
Affected ranges
Type: ECOSYSTEM
Events:
