{"id":"MGASA-2019-0225","summary":"Updated postgresql packages fix security vulnerabilities","details":"Updated postgresql packages fix security vulnerabilities:\n\nGiven a suitable SECURITY DEFINER function, an attacker can execute\narbitrary SQL under the identity of the function owner. An attack requires\nEXECUTE permission on the function, which must itself contain a function\ncall having inexact argument type match. For example, length('foo'::varchar)\nand length('foo') are inexact, while length('foo'::text) is exact\n(CVE-2019-10208).\n\nIn a database containing hypothetical, user-defined hash equality operators,\nan attacker could read arbitrary bytes of server memory. For an attack to\nbecome possible, a superuser would need to create unusual operators. It is\npossible for operators not purpose-crafted for attack to have the properties\nthat enable an attack, but we are not aware of specific examples\n(CVE-2019-10209).\n\nThis update also fixes over 40 bugs that were reported in the last several\nmonths.  See the upstream release notes for details.\n","modified":"2026-04-16T04:44:04.348956921Z","published":"2019-08-18T12:39:41Z","upstream":["CVE-2019-10208","CVE-2019-10209"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2019-0225.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=25260"},{"type":"WEB","url":"https://www.postgresql.org/docs/9.4/release-9-4-24.html"},{"type":"WEB","url":"https://www.postgresql.org/docs/9.6/release-9-6-15.html"},{"type":"WEB","url":"https://www.postgresql.org/docs/11/release-11-5.html"},{"type":"WEB","url":"https://www.postgresql.org/about/news/1960/"}],"affected":[{"package":{"name":"postgresql9.4","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/postgresql9.4?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.4.24-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0225.json"}},{"package":{"name":"postgresql9.6","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/postgresql9.6?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.6.15-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0225.json"}},{"package":{"name":"postgresql9.6","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/postgresql9.6?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.6.15-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0225.json"}},{"package":{"name":"postgresql11","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/postgresql11?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.5-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0225.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}