• [gentoo-announce] [ GLSA 202412-12 ] PostgreSQL: Multiple Vulnerabiliti

    From glsamaker@gentoo.org@21:1/5 to All on Sun Dec 8 09:40:01 2024
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 202412-12
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    https://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: High
    Title: PostgreSQL: Multiple Vulnerabilities
    Date: December 08, 2024
    Bugs: #943512
    ID: 202412-12

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    Multiple vulnerabilities have been discovered in PostgreSQL, the worst
    of which could lead to arbitrary code execution.

    Background
    ==========

    PostgreSQL is an open source object-relational database management
    system.

    Affected packages
    =================

    Package Vulnerable Unaffected
    ----------------- ------------ ------------
    dev-db/postgresql < 12.21:12 >= 12.21:12
    < 13.17:13 >= 13.17:13
    < 14.14:14 >= 14.14:14
    < 15.9:15 >= 15.9:15
    < 16.5:16 >= 16.5:16
    < 17.1:17 >= 17.1:17

    Description
    ===========

    Multiple vulnerabilities have been discovered in PostgreSQL. Please
    review the CVE identifiers referenced below for details.

    Impact
    ======

    Please review the referenced CVE identifiers for details.

    Workaround
    ==========

    There is no known workaround at this time.

    Resolution
    ==========

    All PostgreSQL users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=dev-db/postgresql-12.21:12"
    # emerge --ask --oneshot --verbose ">=dev-db/postgresql-13.17:13"
    # emerge --ask --oneshot --verbose ">=dev-db/postgresql-14.14:14"
    # emerge --ask --oneshot --verbose ">=dev-db/postgresql-15.9:15"
    # emerge --ask --oneshot --verbose ">=dev-db/postgresql-16.5:16"
    # emerge --ask --oneshot --verbose ">=dev-db/postgresql-17.1:17"

    References
    ==========

    [ 1 ] CVE-2024-10976
    https://nvd.nist.gov/vuln/detail/CVE-2024-10976
    [ 2 ] CVE-2024-10977
    https://nvd.nist.gov/vuln/detail/CVE-2024-10977
    [ 3 ] CVE-2024-10978
    https://nvd.nist.gov/vuln/detail/CVE-2024-10978
    [ 4 ] CVE-2024-10979
    https://nvd.nist.gov/vuln/detail/CVE-2024-10979

    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

    https://security.gentoo.org/glsa/202412-12

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users' machines is of utmost
    importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

    License
    =======

    Copyright 2024 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    https://creativecommons.org/licenses/by-sa/2.5
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmdVWOwACgkQFMQkOaVy +9nYTA/8CTM+PPnSFYys1PSBnDFzgUBPGjmeJP5NTAO/3dqgUP/Rk8nBB2JMKKTf JyjhuLx6LryQrbAjxlC7+vENa5ov+lfrE4kpsokZj0azKpRlYIZboedjqyZu7nlA g70R3dlJcjg18Z1ziJWw+HnuvpFly3QSJTSbu2ZKqD+S9BlnSC/DIxVIwSfNGbiZ b7ohCgRvml70fhJ+RN2rfI4qDuAB0Uv50xfsAcK/BEgyHDPtgj33/p7D3kNYmdb2 KAhGy759e2z3Eu4A4QRjo41+1ivXALprCq/d3EykpVAHvC5QePS1O437BKVjA/S5 fD7YNf1qG2+G4HSJmj3bvekjta/0A0f/I92Y0gmPyxDRWLM751mniegi22YQMjb9 d4ZCtbLOBFWHRmG9IQTxIJuYXnVLnmVC+miGjwfZsLoK+1zCcYd1dd9OT+Bwbd/N GeKUoEnreljy2rjlq2TcrF4Wim7hTxrN3045OU2tgTT6wBFFFR9+6y/1DgshzDro R+Em4O17wgTAYWmMEtwVMgmJFjgYvJWZkk0J2B8qXhFQwbOrmAV4sIvnZa5zYPvS Rhv96uqARBzj6voDfdBEJOOYBU/dVVWqihtpCc7q2DBOmR0Qww4PWFza5OwMulL3 QIW5aWGJ4M4oa83iZBCFfNEF5pGRYpiNoD2mPIrZ4qxJNtNl4x0=
    =V2CE
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)