MGASA-2024-0301

Source
https://advisories.mageia.org/MGASA-2024-0301.html
Import Source
https://advisories.mageia.org/MGASA-2024-0301.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2024-0301
Related
Published
2024-09-16T17:44:44Z
Modified
2024-09-16T16:48:16Z
Summary
Updated postgresql15 & postgresql13 packages fix security vulnerability
Details

Time-of-check Time-of-use (TOCTOU) race condition in pgdump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pgdump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. (CVE-2024-7348)

References
Credits

Affected packages