Red Hat Security Advisory: rh-postgresql96-postgresql security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2017-15098 — postgresql: Memory disclosure in JSON functions CVE-2017-15099 — postgresql: INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges CVE-2018-1053 — postgresql: pg_upgrade creates file of sensitive metadata under prevailing umask CVE-2018-1058 — postgresql: Uncontrolled search path element in pg_dump and other client applications CVE-2018-1115 — postgresql: Too-permissive access control list on function pg_logfile_rotate() CVE-2018-10915 — postgresql: Certain host connection parameters defeat client-side security defenses CVE-2018-10925 — postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements
🎯 Affected products200
- Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6)
- Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.7)
- Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.3)
- Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4)
- Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5)
- Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6)
- Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7)
- rh-postgresql96-postgresql-0:9.6.10-1.el6.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6)
- rh-postgresql96-postgresql-0:9.6.10-1.el6.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.7)
- rh-postgresql96-postgresql-0:9.6.10-1.el6.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6)
- rh-postgresql96-postgresql-0:9.6.10-1.el6.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6)
- rh-postgresql96-postgresql-0:9.6.10-1.el6.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 6.7)
- rh-postgresql96-postgresql-0:9.6.10-1.el6.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6)
- rh-postgresql96-postgresql-0:9.6.10-1.el7.aarch64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- rh-postgresql96-postgresql-0:9.6.10-1.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- rh-postgresql96-postgresql-0:9.6.10-1.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.3)
- rh-postgresql96-postgresql-0:9.6.10-1.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4)
- rh-postgresql96-postgresql-0:9.6.10-1.el7.ppc64le as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5)
- rh-postgresql96-postgresql-0:9.6.10-1.el7.s390x as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- rh-postgresql96-postgresql-0:9.6.10-1.el7.s390x as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.3)
- rh-postgresql96-postgresql-0:9.6.10-1.el7.s390x as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4)
- rh-postgresql96-postgresql-0:9.6.10-1.el7.s390x as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5)
- rh-postgresql96-postgresql-0:9.6.10-1.el7.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- rh-postgresql96-postgresql-0:9.6.10-1.el7.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.3)
- rh-postgresql96-postgresql-0:9.6.10-1.el7.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4)
- rh-postgresql96-postgresql-0:9.6.10-1.el7.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5)
- rh-postgresql96-postgresql-0:9.6.10-1.el7.src as a component of Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7)
- rh-postgresql96-postgresql-0:9.6.10-1.el7.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7)
- rh-postgresql96-postgresql-0:9.6.10-1.el7.x86_64 as a component of Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.3)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 If the postgresql service is running, it will be automatically restarted after installing this update. Workaround: Upstream suggests the following mitigation can be used to protect against this security flaw: https://wiki.postgresql.org/wiki/A_Guide_to_CVE-2018-1058:_Protect_Your_Search_Path
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2018:2566
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1508820
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1508823
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1539619
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1547044
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1573276
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1609891
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1612619
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_2566.json