• [SECURITY] [DSA 5135-1] postgresql-11 security update

    From Moritz Muehlenhoff@21:1/5 to All on Thu May 12 21:30:01 2022
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-5135-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff
    May 12, 2022 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : postgresql-11
    CVE ID : CVE-2022-1552

    Alexander Lakhin discovered that the autovacuum feature and multiple
    commands could escape the "security-restricted operation" sandbox.

    For additional information please refer to the upstream announcement
    at https://www.postgresql.org/support/security/CVE-2022-1552/

    For the oldstable distribution (buster), this problem has been fixed
    in version 11.16-0+deb10u1.

    We recommend that you upgrade your postgresql-11 packages.

    For the detailed security status of postgresql-11 please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/postgresql-11

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmJ9XysACgkQEMKTtsN8 TjaHVBAAj18AwRwQOHa0Yym85RlQWTcQVWD7oZIUGP/SSSaBf4fpDJXAK8zQpf6s HjyEnYUJsuUPJo+QkltV0d43RN/KFWivFJOKpdr6RaVDL2n/B6wpKFo4BpBDby/6 4YBdYdOVTqfv9pNF6SbjTQWF2MVpsYX3PP0fJb3TGzHsdeNeE3+4Wk76gSBehVeR Peq9AnL9FpwuLra3Hu6Gy5iPmVbkFZUkkeVE1SqwmX97xPxinm+v0b/xLhClM3du 4pX/BDsKp8ze87cYyFLfryWg6IBjpj9Nu/hIadl4jNdq4iGbHwmZFZ62sHeln/qQ taLZzgmf8/Bni5I5+LpNMJdVWOTk0amWUXA/sgBnjwGuWynV5mKUAUDBDeJfIyaY fg4+9lGOG3etaaA+VDEBg7wW8TwdoGfuOaM6eLgWc7qLudJoZrVSDHGaEa42Xcsr F+/pI5cia7jieKQmZsk2tbBN4hjTmisgqX2wD+wsTzXeZBbmaDOPYVyRBKgUU6w8 SP5bY6Mct7qu3ICafPv//clftsVhqWCHaZScl64wC8zujpT+HHHWPLntlttnB++s wvLpV1EPrVaBgHABKN/84Xchy4L1XFoUgVdPJCSKy6TDwnmneeiFRnphT/l0Ab1E JOp78KkMq3Qmk0KhpHSi+tbt3PqAOBjidAYztnhku7dgqE/v6q0=
    =WmUR
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)