==========================================================================
Ubuntu Security Notice USN-4282-1
February 18, 2020
postgresql-10, postgresql-11 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 19.10
– Ubuntu 18.04 LTS
Summary:
PostgreSQL could allow unintended access to the database.
Software Description:
– postgresql-11: Object-relational SQL database
– postgresql-10: Object-relational SQL database
Details:
It was discovered that PostgreSQL incorrectly performed authorization
checks when handling the “ALTER … DEPENDS ON EXTENSION” sub-commands. A
remote attacker could possibly use this issue to drop any function,
procedure, materialized view, index, or trigger under certain conditions.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 19.10:
postgresql-11 11.7-0ubuntu0.19.10.1
Ubuntu 18.04 LTS:
postgresql-10 10.12-0ubuntu0.18.04.1
This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart PostgreSQL to
make all the necessary changes.
References:
https://usn.ubuntu.com/4282-1
CVE-2020-1720
Package Information:
https://launchpad.net/ubuntu/+source/postgresql-11/11.7-0ubuntu0.19.10.1
https://launchpad.net/ubuntu/+source/postgresql-10/10.12-0ubuntu0.18.04.1
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl5L7pQACgkQZWnYVadE
vpME/w//SHQG9Gc+oOp6q3sW87Ml9zZT/lmJyQk+Q++go8vc2pHTlxeJ9U2u6wlm
jtO796kd8wMF4Y7yuQfp2y8xuKELSuKCGGcExxhgQ6Y/+QWLmJasJ1cAxPB9TRsV
hEk50glx87sj2KQVKQzCaZhr5da2+h8kVgfKz/ejBz3dxU9V2LYzfM7QmEChZj/C
UHs8R5yTN/XC0HR2jPWBbkU1vSS83idQQmFaBO37XJeny3BO2Ap6LAqZKQQ2UqEU
e08NlRqSKhwZgIQDcu8taWAWWIFLaNPscq+bLyVncJm5OGkVDAF7m6ZywT9HtGZx
0EnFD8ZBznnl71q4DoUYMTdwn+m8HzOntB6kOJRrv3Qajxwxe5bp+i/F4xuRAm0o
obIZczP1sh9Klqd+nfz0Sintfp/qHrcUe8Jrc37QBrrfBQyfGksTMOCmiuDBIuzL
mua4mEZ67/F4nHYwZhxCjHwNZbNyl5HRfCMwbGC5T4QmQoDCtTIPTVRBeX0MZcm4
VVwl/cyZe507fiIBfgJO6zZAQOazLabojUFqp+kb/7r3IJfryIjholDmjz2cs6fE
ZqxqxZie6t2xuYaJENpvWFwDQg3Q8M1dGTRwSZHMR703P4CTP+03JuyMe95/HpJA
JiVPq9im2E8/IIIJuP+x/lbtq1C0FaoUVMajyoGh9NoQCxUGzAs=
=nMZU
—–END PGP SIGNATURE—–
—