Bug 57899 - postgresql-11: Multiple issues (5.0)
Summary: postgresql-11: Multiple issues (5.0)
Status: CLOSED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: Security updates
Version: UCS 5.0
Hardware: All Linux
: P3 normal
Target Milestone: UCS 5.0-9-errata
Assignee: Quality Assurance
QA Contact: Christian Castens
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2025-01-27 13:46 CET by Quality Assurance
Modified: 2025-01-29 16:07 CET (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID:
Max CVSS v3 score: 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2025-01-27 13:46:56 CET
New Debian postgresql-11 11.22-0+deb10u4 fixes:
This update addresses the following issues:

Debian update 11.22-0+deb10u4
11.22-0+deb10u4 (Fri, 24 Jan 2025 21:56:25 -0500)
* Non-maintainer upload by the ELTS Team.
* Fix incomplete tracking in PostgreSQL of tables with row security allowing  a reused query to view or change different rows from those intended.  (CVE-2024-10976)
* Fix client use of server error message in PostgreSQL allowing a server not  trusted under current SSL or GSS settings to furnish arbitrary non-NUL  bytes to the libpq application. (CVE-2024-10977)
* Fix incorrect privilege assignment in PostgreSQL allowing a less-privileged  application user to view or change different rows from those intended.  (CVE-2024-10978)
* Fix incorrect control of environment variables in PostgreSQL PL/Perl  allowing an unprivileged database user to change sensitive process  environment variables (e.g. PATH). (CVE-2024-10979)
Comment 1 Quality Assurance univentionstaff 2025-01-27 14:00:08 CET
--- mirror/ftp/pool/main/p/postgresql-11/postgresql-11_11.22-0+deb10u3.dsc
+++ apt/ucs_5.0-0-errata5.0-9/source/postgresql-11_11.22-0+deb10u4.dsc
@@ -1,3 +1,19 @@
+11.22-0+deb10u4 [Fri, 24 Jan 2025 21:56:25 -0500] Roberto C. Sánchez <roberto@debian.org>:
+
+  * Non-maintainer upload by the ELTS Team.
+  * Fix incomplete tracking in PostgreSQL of tables with row security allowing
+    a reused query to view or change different rows from those intended.
+    (CVE-2024-10976)
+  * Fix client use of server error message in PostgreSQL allowing a server not
+    trusted under current SSL or GSS settings to furnish arbitrary non-NUL
+    bytes to the libpq application. (CVE-2024-10977)
+  * Fix incorrect privilege assignment in PostgreSQL allowing a
+    less-privileged application user to view or change different rows from
+    those intended. (CVE-2024-10978)
+  * Fix incorrect control of environment variables in PostgreSQL PL/Perl
+    allowing an unprivileged database user to change sensitive process
+    environment variables (e.g. PATH). (CVE-2024-10979)
+
 11.22-0+deb10u3 [Fri, 30 Aug 2024 15:53:22 -0400] Roberto C. Sánchez <roberto@debian.org>:
 
   * Non-maintainer upload by the ELTS Team.

<http://piuparts.knut.univention.de/5.0-9/#5129848423135722452>
Comment 2 Christian Castens univentionstaff 2025-01-28 14:11:34 CET
OK: bug
OK: yaml
OK: announce_errata
OK: patch
OK: piuparts

[5.0-9] 1d72261d0f Bug #57899: postgresql-11 11.22-0+deb10u4
 doc/errata/staging/postgresql-11.yaml | 20 ++++++++++++++++++++
 1 file changed, 20 insertions(+)
Comment 3 Christian Castens univentionstaff 2025-01-29 16:07:43 CET
<https://errata.software-univention.de/#/?erratum=5.0x1205>