Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 943512 (CVE-2024-10976, CVE-2024-10977, CVE-2024-10978, CVE-2024-10979) - <dev-db/postgresql-{12.21,13.17,14.14,15.9,16.5,17.1}: Multiple vulnerabilities
Summary: <dev-db/postgresql-{12.21,13.17,14.14,15.9,16.5,17.1}: Multiple vulnerabilities
Status: CONFIRMED
Alias: CVE-2024-10976, CVE-2024-10977, CVE-2024-10978, CVE-2024-10979
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://www.postgresql.org/about/news...
Whiteboard: B1 [glsa? cleanup]
Keywords:
Depends on: 943513
Blocks:
  Show dependency tree
 
Reported: 2024-11-14 15:02 UTC by Patrick Lauer
Modified: 2024-11-15 16:06 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Patrick Lauer gentoo-dev 2024-11-14 15:02:42 UTC
From the announcement:

CVE-2024-10976: PostgreSQL row security below e.g. subqueries disregards user ID changes

CVE-2024-10977: PostgreSQL libpq retains an error message from man-in-the-middle

CVE-2024-10978: PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID

CVE-2024-10979: PostgreSQL PL/Perl environment variable changes execute arbitrary code