[Apollo] Advisories Statistics light light Login

RLSA-2023:7785

Security Mirrored from RHSA-2023:7785
Issued at: 2024-01-09
Updated at: 2026-02-07

Synopsis

Important: postgresql:15 security update



Description

PostgreSQL is an advanced object-relational database management system (DBMS).

Security Fix(es):

* postgresql: Buffer overrun from integer overflow in array modification (CVE-2023-5869)

* postgresql: Memory disclosure in aggregate function calls (CVE-2023-5868)

* postgresql: extension script @substitutions@ within quoting allow SQL injection (CVE-2023-39417)

* postgresql: Role pg_signal_backend can signal certain superuser processes. (CVE-2023-5870)

* postgresql: MERGE fails to enforce UPDATE or SELECT row security policies (CVE-2023-39418)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 9 x86_64

Fixes

2228111 2228112 2247168 2247169 2247170

CVEs

CVE-2023-39417 CVE-2023-39418 CVE-2023-5868 CVE-2023-5869 CVE-2023-5870

Affected packages

Rocky Linux 9 x86_64 - AppStream

pgaudit-0:1.7.0-1.module+el9.7.0+40011+28af63c9.src.rpm pgaudit-0:1.7.0-1.module+el9.7.0+40011+28af63c9.x86_64.rpm pgaudit-debuginfo-0:1.7.0-1.module+el9.7.0+40011+28af63c9.x86_64.rpm pgaudit-debugsource-0:1.7.0-1.module+el9.7.0+40011+28af63c9.x86_64.rpm postgres-decoderbufs-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.src.rpm postgres-decoderbufs-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.x86_64.rpm postgres-decoderbufs-debuginfo-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.x86_64.rpm postgres-decoderbufs-debugsource-0:1.9.7-1.Final.module+el9.7.0+40011+28af63c9.x86_64.rpm