RHSA-2020:5620: Important: postgresql:12 security update
PostgreSQL is an advanced object-relational database management system (DBMS).The following packages have been upgraded to a later upstream version: postgresql (12.5).Security Fix(es): postgresql: Reconnection can downgrade connection security settings (CVE-2020-25694) postgresql: Multiple features escape "security restricted operation" sandbox (CVE-2020-25695) postgresql: Uncontrolled search path element in logical replication (CVE-2020-14349) postgresql: Uncontrolled search path element in CREATE EXTENSION (CVE-2020-14350) postgresql: psql's \gset allows overwriting specially treated variables (CVE-2020-25696) postgresql: ALTER ... DEPENDS ON EXTENSION is missing authorization checks (CVE-2020-1720) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/pgauditto a version that resolves this vulnerability.Fixed in 1.4.0-4.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgres-decoderbufsto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresqlto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/pgaudit-debuginfoto a version that resolves this vulnerability.Fixed in 1.4.0-4.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/pgaudit-debugsourceto a version that resolves this vulnerability.Fixed in 1.4.0-4.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgres-decoderbufs-debuginfoto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgres-decoderbufs-debugsourceto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-contribto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-contrib-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-debugsourceto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-docsto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-docs-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-plperlto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-plperl-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-plpython3to a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-plpython3-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-pltclto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-pltcl-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-serverto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-server-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-server-develto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-server-devel-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-staticto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-testto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-test-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-test-rpm-macrosto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-upgradeto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-upgrade-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-upgrade-develto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/postgresql-upgrade-devel-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4 - Upgrade
Upgrade
redhat/pgauditto a version that resolves this vulnerability.Fixed in 1.4.0-4.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/pgaudit-debuginfoto a version that resolves this vulnerability.Fixed in 1.4.0-4.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/pgaudit-debugsourceto a version that resolves this vulnerability.Fixed in 1.4.0-4.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgres-decoderbufsto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgres-decoderbufs-debuginfoto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgres-decoderbufs-debugsourceto a version that resolves this vulnerability.Fixed in 0.10.0-2.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresqlto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-contribto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-contrib-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-debugsourceto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-docsto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-docs-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-plperlto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-plperl-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-plpython3to a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-plpython3-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-pltclto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-pltcl-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-serverto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-server-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-server-develto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-server-devel-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-staticto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-testto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-test-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-upgradeto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-upgrade-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-upgrade-develto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
redhat/postgresql-upgrade-devel-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-1.module+el8.3.0+9042+664538f4.aa - Upgrade
Upgrade
postgresqlto a version that resolves this vulnerability.Fixed in 12.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2020-25694 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2020-25695 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2020-14350 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2020-14349 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2020-25696 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2020-1720
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:5620?
The severity of RHSA-2020:5620 is categorized as moderate.
How do I fix RHSA-2020:5620?
To fix RHSA-2020:5620, upgrade the affected PostgreSQL packages to version 12.5-1.module+el8.3.0+9042+664538f4 or later.
What vulnerabilities are addressed in RHSA-2020:5620?
RHSA-2020:5620 addresses a vulnerability where reconnection can downgrade connection security settings, identified as CVE-2020-25694.
Which packages are affected by RHSA-2020:5620?
The packages affected by RHSA-2020:5620 include postgresql, pgaudit, and postgres-decoderbufs, among others.
Is RHSA-2020:5620 relevant for PostgreSQL users?
Yes, RHSA-2020:5620 is relevant for PostgreSQL users running affected versions, and they should take action to mitigate the vulnerability.