Advisories ยป MGASA-2023-0261

Updated postgresql packages fix security vulnerability

Publication date: 11 Sep 2023
Modification date: 11 Sep 2023
Type: security
Affected Mageia releases : 8 , 9
CVE: CVE-2023-39417 , CVE-2023-39418

Description

Extension script @substitutions@ within quoting allow SQL injection.
(CVE-2023-39417)

MERGE fails to enforce UPDATE or SELECT row security policies.
(CVE-2023-39418)
                

References

SRPMS

8/core

9/core