Hi,

PostgreSQL 16.4, 15.8, 14.13, 13.16, 12.20 released on August 8 fix the
below security issue.

Content from https://www.postgresql.org/support/security/CVE-2024-7348/

> CVE-2024-7348
> PostgreSQL relation replacement during pg_dump executes arbitrary SQL
> 
> Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in
> PostgreSQL allows an object creator to execute arbitrary SQL functions
> as the user running pg_dump, which is often a superuser. The attack
> involves replacing another relation type with a view or foreign table.
> The attack requires waiting for pg_dump to start, but winning the race
> condition is trivial if the attacker retains an open transaction.
> Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are
> affected.
> 
> The PostgreSQL project thanks Noah Misch for reporting this problem.

> CVSS 3.0
> Overall Score         8.8
> Component     core server
> Vector        AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Alexander

Reply via email to