Package | postgresql-9.4 |
---|---|
Version | 9.4.26-0+deb8u6 |
Related CVEs | CVE-2022-2625 CVE-2022-1552 |
-
CVE-2022-2625
Sven Klemm found that some extensions in the PostgreSQL database system could replace objects not belonging to the extension. An attacker could leverage this to run arbitrary commands as another user.
-
CVE-2022-1552
Alexander Lakhin discovered that the autovacuum feature and multiple commands could escape the “security-restricted operation” sandbox.
For Debian 8 jessie, these problems have been fixed in version 9.4.26-0+deb8u6.
We recommend that you upgrade your postgresql-9.4 packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.