RHSA-2020:5401: Important: libpq security update
The libpq package provides the PostgreSQL client library, which allows client programs to connect to PostgreSQL servers. The following packages have been upgraded to a later upstream version: libpq (12.5). (BZ#1898228, BZ#1901558)Security Fix(es): postgresql: Reconnection can downgrade connection security settings (CVE-2020-25694) postgresql: psql's \gset allows overwriting specially treated variables (CVE-2020-25696) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libpqto a version that resolves this vulnerability.Fixed in 12.5-1.el8_3 - Upgrade
Upgrade
redhat/libpq-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.el8_3 - Upgrade
Upgrade
redhat/libpq-debugsourceto a version that resolves this vulnerability.Fixed in 12.5-1.el8_3 - Upgrade
Upgrade
redhat/libpq-develto a version that resolves this vulnerability.Fixed in 12.5-1.el8_3 - Upgrade
Upgrade
redhat/libpq-devel-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.el8_3 - Upgrade
Upgrade
redhat/libpqto a version that resolves this vulnerability.Fixed in 12.5-1.el8_3.aa - Upgrade
Upgrade
redhat/libpq-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.el8_3.aa - Upgrade
Upgrade
redhat/libpq-debugsourceto a version that resolves this vulnerability.Fixed in 12.5-1.el8_3.aa - Upgrade
Upgrade
redhat/libpq-develto a version that resolves this vulnerability.Fixed in 12.5-1.el8_3.aa - Upgrade
Upgrade
redhat/libpq-devel-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.el8_3.aa - Upgrade
Upgrade
libpqto a version that resolves this vulnerability.Fixed in 12.5Patch BZ#1898228 - Upgrade
Upgrade
postgresqlto a version that resolves this vulnerability.Patch BZ#1901558
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:5401?
The severity of RHSA-2020:5401 is categorized as important due to a security vulnerability in the PostgreSQL client library.
How do I fix RHSA-2020:5401?
To fix RHSA-2020:5401, upgrade the libpq package to version 12.5-1.el8_3 or later.
What packages are affected by RHSA-2020:5401?
The affected packages include libpq, libpq-devel, libpq-debuginfo, and libpq-debugsource.
Is there a workaround for RHSA-2020:5401?
There are no officially recommended workarounds for RHSA-2020:5401; the best approach is to apply the patch.
When was RHSA-2020:5401 released?
RHSA-2020:5401 was released on December 8, 2020.