RHSA-2020:3669: Moderate: postgresql:10 security and bug fix update
PostgreSQL is an advanced object-relational database management system (DBMS).The following packages have been upgraded to a later upstream version: postgresql (10.14).Security Fix(es): postgresql: Stack-based buffer overflow via setting a password (CVE-2019-10164) postgresql: TYPE in pgtemp executes arbitrary SQL during SECURITY DEFINER execution (CVE-2019-10208) postgresql: Uncontrolled search path element in logical replication (CVE-2020-14349) postgresql: Uncontrolled search path element in CREATE EXTENSION (CVE-2020-14350) postgresql: Selectivity estimators bypass row security policies (CVE-2019-10130) postgresql: ALTER ... DEPENDS ON EXTENSION is missing authorization checks (CVE-2020-1720) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Module stream postgresql:10 does not have correct module.md file (BZ#1857228)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/postgresqlto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-contribto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-contrib-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-debugsourceto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-docsto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-docs-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-plperlto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-plperl-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-plpython3to a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-plpython3-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-pltclto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-pltcl-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-serverto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-server-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-server-develto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-server-devel-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-staticto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-testto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-test-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-test-rpm-macrosto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-upgradeto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-upgrade-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-upgrade-develto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresql-upgrade-devel-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80 - Upgrade
Upgrade
redhat/postgresqlto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-contribto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-contrib-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-debugsourceto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-docsto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-docs-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-plperlto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-plperl-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-plpython3to a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-plpython3-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-pltclto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-pltcl-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-serverto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-server-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-server-develto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-server-devel-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-staticto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-testto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-test-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-test-rpm-macrosto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-upgradeto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-upgrade-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-upgrade-develto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
redhat/postgresql-upgrade-devel-debuginfoto a version that resolves this vulnerability.Fixed in 10.14-1.module+el8.2.0+7801+be0fed80.aa - Upgrade
Upgrade
postgresqlto a version that resolves this vulnerability.Fixed in 10.14 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch BZ#1857228
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3669?
The severity of RHSA-2020:3669 is rated as important due to a stack-based buffer overflow vulnerability.
How do I fix RHSA-2020:3669?
To fix RHSA-2020:3669, upgrade the affected PostgreSQL packages to version 10.14-1.module+el8.2.0+7801+be0fed80.
Which PostgreSQL versions are affected by RHSA-2020:3669?
RHSA-2020:3669 affects PostgreSQL versions prior to 10.14-1.module+el8.2.0+7801+be0fed80.
What are the components impacted by RHSA-2020:3669?
The components affected by RHSA-2020:3669 include postgresql, postgresql-contrib, and their associated debug and documentation packages.
Is there a known exploit for RHSA-2020:3669?
As of now, there are no known public exploits for RHSA-2020:3669, but it is advisable to patch the vulnerability promptly.