USN-6656-1: PostgreSQL vulnerability
It was discovered that PostgreSQL incorrectly handled dropping privileges when handling REFRESH MATERIALIZED VIEW CONCURRENTLY commands. If a user or automatic system were tricked into running a specially crafted command, a remote attacker could possibly use this issue to execute arbitrary SQL functions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6656-1?
The severity of USN-6656-1 is significant as it could allow a remote attacker to execute arbitrary commands.
How do I fix USN-6656-1?
You can fix USN-6656-1 by updating PostgreSQL to the recommended version 15.6-0ubuntu0.23.10.1 or later.
Who is affected by USN-6656-1?
USN-6656-1 affects users of PostgreSQL versions 12, 14, and 15 on Ubuntu versions 20.04, 22.04, and 23.10.
What versions of PostgreSQL are impacted by USN-6656-1?
USN-6656-1 impacts PostgreSQL versions 12, 14, and 15 on specified Ubuntu releases.
What commands are related to the vulnerability in USN-6656-1?
The vulnerability in USN-6656-1 is related to the REFRESH MATERIALIZED VIEW CONCURRENTLY commands.