RHSA-2021:0165: Important: libpq security update
The libpq package provides the PostgreSQL client library, which allows client programs to connect to PostgreSQL servers. The following packages have been upgraded to a later upstream version: libpq (12.5). (BZ#1898226, BZ#1901561)Security Fix(es): postgresql: Reconnection can downgrade connection security settings (CVE-2020-25694) postgresql: psql's \gset allows overwriting specially treated variables (CVE-2020-25696) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libpqto a version that resolves this vulnerability.Fixed in 12.5-2.el8_1 - Upgrade
Upgrade
redhat/libpq-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-2.el8_1 - Upgrade
Upgrade
redhat/libpq-debugsourceto a version that resolves this vulnerability.Fixed in 12.5-2.el8_1 - Upgrade
Upgrade
redhat/libpq-develto a version that resolves this vulnerability.Fixed in 12.5-2.el8_1 - Upgrade
Upgrade
redhat/libpq-devel-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-2.el8_1 - Upgrade
Upgrade
redhat/libpqto a version that resolves this vulnerability.Fixed in 12.5-2.el8_1.aa - Upgrade
Upgrade
redhat/libpq-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-2.el8_1.aa - Upgrade
Upgrade
redhat/libpq-debugsourceto a version that resolves this vulnerability.Fixed in 12.5-2.el8_1.aa - Upgrade
Upgrade
redhat/libpq-develto a version that resolves this vulnerability.Fixed in 12.5-2.el8_1.aa - Upgrade
Upgrade
redhat/libpq-devel-debuginfoto a version that resolves this vulnerability.Fixed in 12.5-2.el8_1.aa - Upgrade
Upgrade
libpqto a version that resolves this vulnerability.Fixed in 12.5-2.el8_1 - Upgrade
Upgrade
libpq-develto a version that resolves this vulnerability.Fixed in 12.5-2.el8_1
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:0165?
The severity of RHSA-2021:0165 is classified as important.
How do I fix RHSA-2021:0165?
To fix RHSA-2021:0165, upgrade the libpq, libpq-debuginfo, libpq-debugsource, and libpq-devel packages to version 12.5-2.el8_1.
Which packages are affected by RHSA-2021:0165?
The affected packages include libpq, libpq-debuginfo, libpq-debugsource, and libpq-devel on various architectures.
What vulnerabilities does RHSA-2021:0165 address?
RHSA-2021:0165 addresses vulnerabilities related to the PostgreSQL client library that could affect connectivity and security.
Is there a recommended version for the packages fixed by RHSA-2021:0165?
The recommended version for the packages fixed by RHSA-2021:0165 is 12.5-2.el8_1.