RHSA-2018:2566: Important: rh-postgresql96-postgresql security update
PostgreSQL is an advanced object-relational database management system (DBMS).<br>The following packages have been upgraded to a later upstream version: rh-postgresql96-postgresql (9.6.10). (BZ#1614340)<br>Security Fix(es):<br><li> postgresql: Certain host connection parameters defeat client-side security defenses (CVE-2018-10915)</li> <li> postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements (CVE-2018-10925)</li> <li> postgresql: Memory disclosure in JSON functions (CVE-2017-15098)</li> <li> postgresql: pgupgrade creates file of sensitive metadata under prevailing umask (CVE-2018-1053)</li> <li> postgresql: Uncontrolled search path element in pgdump and other client applications (CVE-2018-1058)</li> <li> postgresql: INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges (CVE-2017-15099)</li> <li> postgresql: Too-permissive access control list on function pglogfilerotate() (CVE-2018-1115)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Red Hat would like to thank the PostgreSQL project for reporting CVE-2018-10915, CVE-2018-10925, CVE-2017-15098, CVE-2018-1053, CVE-2017-15099, and CVE-2018-1115. Upstream acknowledges Andrew Krasichkov as the original reporter of CVE-2018-10915; David Rowley as the original reporter of CVE-2017-15098; Tom Lane as the original reporter of CVE-2018-1053; Dean Rasheed as the original reporter of CVE-2017-15099; and Stephen Frost as the original reporter of CVE-2018-1115.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2018:2566?
RHSA-2018:2566 is rated as important due to the potential impact on database security.
How do I fix RHSA-2018:2566?
To fix RHSA-2018:2566, upgrade to the patched version rh-postgresql96-postgresql-9.6.10-1.el7 or later.
What packages are affected by RHSA-2018:2566?
Affected packages include rh-postgresql96-postgresql and other related packages such as rh-postgresql96-postgresql-contrib.
What is the purpose of RHSA-2018:2566?
The purpose of RHSA-2018:2566 is to address vulnerabilities that could allow unauthorized access to the PostgreSQL database.
Is RHSA-2018:2566 applicable to all versions of PostgreSQL?
No, RHSA-2018:2566 specifically applies to the 9.6 version of the PostgreSQL package provided by Red Hat.