MGASA-2024-0301

Source
https://advisories.mageia.org/MGASA-2024-0301.html
Import Source
https://advisories.mageia.org/MGASA-2024-0301.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2024-0301
Related
Published
2024-09-16T17:44:44Z
Modified
2024-09-16T16:48:16Z
Summary
Updated postgresql15 & postgresql13 packages fix security vulnerability
Details

Time-of-check Time-of-use (TOCTOU) race condition in pgdump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pgdump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. (CVE-2024-7348)

References
Credits

Affected packages

Mageia:9 / postgresql15

Package

Name
postgresql15
Purl
pkg:rpm/mageia/postgresql15?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
15.8-1.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:9 / postgresql13

Package

Name
postgresql13
Purl
pkg:rpm/mageia/postgresql13?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
13.16-1.mga9

Ecosystem specific

{
    "section": "core"
}