[ubuntu/xenial-security] postgresql-9.5 9.5.23-0ubuntu0.16.04.1 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Tue Aug 25 12:12:14 UTC 2020
postgresql-9.5 (9.5.23-0ubuntu0.16.04.1) xenial-security; urgency=medium
* New upstream release (LP: #1892335).
- Make contrib modules' installation scripts more secure (Tom Lane)
Attacks similar to those described in CVE-2018-1058 could be carried out
against an extension installation script, if the attacker can create
objects in either the extension's target schema or the schema of some
prerequisite extension. Since extensions often require superuser
privilege to install, this can open a path to obtaining superuser
privilege. To mitigate this risk, be more careful about the search_path
used to run an installation script; disable check_function_bodies within
the script; and fix catalog-adjustment queries used in some contrib
modules to ensure they are secure. Also provide documentation to help
third-party extension authors make their installation scripts secure.
This is not a complete solution; extensions that depend on other
extensions can still be at risk if installed carelessly.
CVE-2020-14350
- Details about these and many further changes can be found at:
https://www.postgresql.org/docs/9.5/static/release-9-5-22.html
https://www.postgresql.org/docs/9.5/static/release-9-5-23.html
postgresql-9.5 (9.5.21-0ubuntu0.16.04.1) xenial; urgency=medium
* New upstream release (LP: #1863108)
- A dump/restore is not required however, if you use the contrib/intarray
extension with a GiST index, and you rely on indexed searches for the <@
operator, see the release notes for details in regard to a related fix.
- Details about these and many further changes can be found at:
https://www.postgresql.org/docs/9.5/static/release-9-5-20.html
https://www.postgresql.org/docs/9.5/static/release-9-5-21.html
Date: 2020-08-20 18:09:27.336808+00:00
Changed-By: Christian Ehrhardt <christian.ehrhardt at canonical.com>
Signed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Xenial-changes
mailing list