{"id":"MGASA-2016-0289","summary":"Updated postgresql packages fix security vulnerability","details":"It was discovered that certain SQL statements containing CASE/WHEN\ncommands could crash the PostgreSQL server, or disclose a few bytes of\nserver memory, potentially leading to arbitrary code execution\n(CVE-2016-5423).\n\nIt was found that PostgreSQL client programs mishandle database and role\nnames containing newlines, carriage returns, double quotes, or\nbackslashes. By crafting such an object name, roles with the CREATEDB or\nCREATEROLE option could escalate their privileges to root when a root user\nnext executes maintenance with a vulnerable program. Vulnerable programs\ninclude pg_dumpall, pg_upgrade, vacuumdb, reindexdb, and clusterdb\n(CVE-2016-5424).\n","modified":"2026-04-16T06:22:58.714905988Z","published":"2016-08-31T15:32:33Z","upstream":["CVE-2016-5423","CVE-2016-5424"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0289.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=19183"},{"type":"WEB","url":"http://www.postgresql.org/docs/current/static/release-9-3-14.html"},{"type":"WEB","url":"http://www.postgresql.org/docs/current/static/release-9-4-9.html"},{"type":"WEB","url":"https://www.postgresql.org/about/news/1688/"}],"affected":[{"package":{"name":"postgresql9.3","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/postgresql9.3?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.3.14-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0289.json"}},{"package":{"name":"postgresql9.4","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/postgresql9.4?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.4.9-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0289.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}