New Debian postgresql-11 11.22-0+deb10u4 fixes: This update addresses the following issues: Debian update 11.22-0+deb10u4 11.22-0+deb10u4 (Fri, 24 Jan 2025 21:56:25 -0500) * Non-maintainer upload by the ELTS Team. * Fix incomplete tracking in PostgreSQL of tables with row security allowing a reused query to view or change different rows from those intended. (CVE-2024-10976) * Fix client use of server error message in PostgreSQL allowing a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. (CVE-2024-10977) * Fix incorrect privilege assignment in PostgreSQL allowing a less-privileged application user to view or change different rows from those intended. (CVE-2024-10978) * Fix incorrect control of environment variables in PostgreSQL PL/Perl allowing an unprivileged database user to change sensitive process environment variables (e.g. PATH). (CVE-2024-10979)
--- mirror/ftp/pool/main/p/postgresql-11/postgresql-11_11.22-0+deb10u3.dsc +++ apt/ucs_5.0-0-errata5.0-9/source/postgresql-11_11.22-0+deb10u4.dsc @@ -1,3 +1,19 @@ +11.22-0+deb10u4 [Fri, 24 Jan 2025 21:56:25 -0500] Roberto C. Sánchez <roberto@debian.org>: + + * Non-maintainer upload by the ELTS Team. + * Fix incomplete tracking in PostgreSQL of tables with row security allowing + a reused query to view or change different rows from those intended. + (CVE-2024-10976) + * Fix client use of server error message in PostgreSQL allowing a server not + trusted under current SSL or GSS settings to furnish arbitrary non-NUL + bytes to the libpq application. (CVE-2024-10977) + * Fix incorrect privilege assignment in PostgreSQL allowing a + less-privileged application user to view or change different rows from + those intended. (CVE-2024-10978) + * Fix incorrect control of environment variables in PostgreSQL PL/Perl + allowing an unprivileged database user to change sensitive process + environment variables (e.g. PATH). (CVE-2024-10979) + 11.22-0+deb10u3 [Fri, 30 Aug 2024 15:53:22 -0400] Roberto C. Sánchez <roberto@debian.org>: * Non-maintainer upload by the ELTS Team. <http://piuparts.knut.univention.de/5.0-9/#5129848423135722452>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.0-9] 1d72261d0f Bug #57899: postgresql-11 11.22-0+deb10u4 doc/errata/staging/postgresql-11.yaml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.0x1205>