Lukas Fittl discovered that PostgreSQL incorrectly performed authorization in the built-in pgstatsext and pgstatsext_exprs views. An unprivileged database user can use this issue to read most common values and other statistics from CREATE STATISTICS commands of other users.
NOTE: This update will only fix fresh PostgreSQL installations. Current PostgreSQL installations will remain vulnerable to this issue until manual steps are performed. Please see the instructions in the changelog located at /usr/share/doc/postgresql-*/changelog.Debian.gz after the updated packages have been installed, or in the PostgreSQL release notes located here:
https://www.postgresql.org/docs/16/release-16-3.html https://www.postgresql.org/docs/15/release-15-7.html https://www.postgresql.org/docs/14/release-14-12.html
{ "availability": "No subscription required", "binaries": [ { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "libecpg-compat3" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "libecpg-compat3-dbgsym" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "libecpg-dev" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "libecpg-dev-dbgsym" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "libecpg6" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "libecpg6-dbgsym" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "libpgtypes3" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "libpgtypes3-dbgsym" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "libpq-dev" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "libpq5" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "libpq5-dbgsym" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "postgresql-14" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "postgresql-14-dbgsym" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "postgresql-client-14" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "postgresql-client-14-dbgsym" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "postgresql-doc-14" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "postgresql-plperl-14" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "postgresql-plperl-14-dbgsym" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "postgresql-plpython3-14" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "postgresql-plpython3-14-dbgsym" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "postgresql-pltcl-14" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "postgresql-pltcl-14-dbgsym" }, { "binary_version": "14.12-0ubuntu0.22.04.1", "binary_name": "postgresql-server-dev-14" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "libecpg-compat3" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "libecpg-compat3-dbgsym" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "libecpg-dev" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "libecpg-dev-dbgsym" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "libecpg6" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "libecpg6-dbgsym" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "libpgtypes3" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "libpgtypes3-dbgsym" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "libpq-dev" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "libpq5" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "libpq5-dbgsym" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "postgresql-15" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "postgresql-15-dbgsym" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "postgresql-client-15" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "postgresql-client-15-dbgsym" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "postgresql-doc-15" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "postgresql-plperl-15" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "postgresql-plperl-15-dbgsym" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "postgresql-plpython3-15" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "postgresql-plpython3-15-dbgsym" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "postgresql-pltcl-15" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "postgresql-pltcl-15-dbgsym" }, { "binary_version": "15.7-0ubuntu0.23.10.1", "binary_name": "postgresql-server-dev-15" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "libecpg-compat3" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "libecpg-compat3-dbgsym" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "libecpg-dev" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "libecpg-dev-dbgsym" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "libecpg6" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "libecpg6-dbgsym" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "libpgtypes3" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "libpgtypes3-dbgsym" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "libpq-dev" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "libpq5" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "libpq5-dbgsym" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "postgresql-16" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "postgresql-16-dbgsym" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "postgresql-client-16" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "postgresql-client-16-dbgsym" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "postgresql-doc-16" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "postgresql-plperl-16" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "postgresql-plperl-16-dbgsym" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "postgresql-plpython3-16" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "postgresql-plpython3-16-dbgsym" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "postgresql-pltcl-16" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "postgresql-pltcl-16-dbgsym" }, { "binary_version": "16.3-0ubuntu0.24.04.1", "binary_name": "postgresql-server-dev-16" } ] }