-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ----------------------------------------------------------------------- Debian LTS Advisory DLA-3600-1 [email protected] https://www.debian.org/lts/security/ Utkarsh Gupta October 04, 2023 https://wiki.debian.org/LTS - -----------------------------------------------------------------------
Package : postgresql-11 Version : 11.21-0+deb10u2 CVE ID : CVE-2023-39417 A SQL Injection vulnerability was found in PostgreSQL, an object-relational SQL database management system. An extension script is vulnerable if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). For Debian 10 buster, this problem has been fixed in version 11.21-0+deb10u2. We recommend that you upgrade your postgresql-11 packages. For the detailed security status of postgresql-11 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/postgresql-11 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmUcjhIACgkQgj6WdgbD S5bM1w/+Nkte5MeS+uFnv9dUjAu2SGeb/UQZ4S+LdE8tvGwu3ab0G6f5j8+00arx FI5YO+/4UAVHCm9UjyCDUieEA9dK0uQPsz0Yw9q6YzM6QCXdbBw/DY3RoGSW20BB c35kdPCMipxH/Byp53u2CjeMEe2DBh3qqIWD7n1BS+5umaq561iv3K+ZP/VWAQs6 yoVhMkEgH4aW4estrsPlioJyii7hovnDUoxQIRFCU6d8SZbyHGStb81b6ZySv5aR w7DZTvM9lg28l91uM3tat2aK1nCQkkhOPIaPbFGR4l47eQUbtmUqyZy9MOU/iLLq JuuoMKTp7630ZYffoPdjOPcvSX5KDmoVd7j5G0ClPUV3Oz/uuXrqW+NagQ0R2cXZ hFYUG61Y+FL3N6Nmz9poBdZ0wslTnmZpardsUOOTtlFCGo5SYXdR/VaAWeqQq9DG dtlzjBHaoAIZivn/KJ2GXCVp3L5peNe4KwZ6nAetEkQP4knTDRA5Bgu/wQ1gFz+L bLCuRW7YURZMU/5YtvQEIbFKlrigpxxbmIaqekSvLp+R4jpq9YI1UxqqPoU79Ooy Sqopo6x3aBC5300RRgpD3FDLy3RfDqzwYt1+770NzR7e9S7sP2t6JYkSzi3wMpf3 gtYvty60Hj7Q8PvWeG323DW69+xCeBirHsr67p7/coMWFk+6Cb0= =Cstz -----END PGP SIGNATURE-----
