First published: Wed Nov 04 2020(Updated: )
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic connection parameters while dropping security-relevant parameters, an opportunity for a man-in-the-middle attack, or the ability to observe clear-text transmissions, could exist. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/postgresql | <0:9.2.24-6.el7_9 | 0:9.2.24-6.el7_9 |
redhat/libpq | <0:12.5-1.el8_3 | 0:12.5-1.el8_3 |
redhat/libpq | <0:12.5-1.el8_0 | 0:12.5-1.el8_0 |
redhat/libpq | <0:12.5-2.el8_1 | 0:12.5-2.el8_1 |
redhat/libpq | <0:12.5-1.el8_2 | 0:12.5-1.el8_2 |
redhat/rh-postgresql10-postgresql | <0:10.15-1.el7 | 0:10.15-1.el7 |
redhat/rh-postgresql12-postgresql | <0:12.5-1.el7 | 0:12.5-1.el7 |
redhat/postgresql | <13.1 | 13.1 |
redhat/postgresql | <12.5 | 12.5 |
redhat/postgresql | <11.10 | 11.10 |
redhat/postgresql | <10.15 | 10.15 |
redhat/postgresql | <9.6.20 | 9.6.20 |
redhat/postgresql | <9.5.24 | 9.5.24 |
PostgreSQL PostgreSQL | <9.5.24 | |
PostgreSQL PostgreSQL | >=9.6.0<9.6.20 | |
PostgreSQL PostgreSQL | >=10.0<10.15 | |
PostgreSQL PostgreSQL | >=11.0<11.10 | |
PostgreSQL PostgreSQL | >=12.0<12.5 | |
PostgreSQL PostgreSQL | >=13.0<13.1 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-25694 is a vulnerability found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24.
CVE-2020-25694 has a severity score of 8.1, which is considered high.
CVE-2020-25694 affects PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24.
To fix CVE-2020-25694, upgrade to PostgreSQL version 13.1, 12.5, 11.10, 10.15, or 9.6.20.
You can find more information about CVE-2020-25694 in the Red Hat Bugzilla references: https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1897234, https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1897231, https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1897222.