Collected every two hours from specialised publications — each link leads to the original article.
Several security vulnerabilities have been found in libpgjava, the official PostgreSQL JDBC Driver. CVE-2020-13692
It was found that libpgjava, the official PostgreSQL JDBC Driver, would be vulnerable if an attacker controlled jdbc url or properties. The JDBC driver did not…
Potential SQL injection in QuerySet.annotate(), aggregate(), and extra() (CVE-2022-28346) Potential SQL injection via QuerySet.explain(**options) on PostgreSQL…
**MariaDB 10.5.15** Release notes: https://mariadb.com/kb/en/mariadb-10515-release-notes/
Emmet Leahy reported that libphp-adodb, a PHP database abstraction layer library, allows to inject values into a PostgreSQL connection string. Depending on how…
It was found that PgBouncer, a PostgreSQL connection pooler, was susceptible to an arbitrary SQL injection attack if a man-in-the-middle could inject data when…
Security hotfix release addressing a critical vulnerability in PostgreSQL connections (CVE-2021-3850) Additional fixes: Fix usage of get_magic_* functions #619…
It was found that in libphp-adodb, a PHP database abstraction layer library, an attacker can inject values into the PostgreSQL connection string by bypassing a…
Update to 1.16.1, per changes decribed at: http://www.pgbouncer.org/changelog.html#pgbouncer-116x Fixes multiple security vulnerabilities related to PostgreSQL…
The regression of postgresql-9.6-postgis-2.3-scripts being empty in 2.3.1+dfsg-2+deb9u1 has been fixed. For Debian 9 stretch, this problem has been fixed in ve…
In PostGIS, which adds support for geographic objects to the PostgreSQL database, denial of service via crafted ST_AsX3D function input was fixed.
**Version 4.4.35** (2021-11-24) * security **CVE-2021-41270** [Serializer] Use single quote to escape formulas (jderusse) * bug #44232 [Cache] fix connecting t…
**Version 4.4.35** (2021-11-24) * security **CVE-2021-41270** [Serializer] Use single quote to escape formulas (jderusse) * bug #44232 [Cache] fix connecting t…
**PHP version 7.4.26** (18 Nov 2021) **Core:** * Fixed bug php#81518 (Header injection via default_mimetype / default_charset). (cmb) **Date:** * Fixed bug php…
**PHP version 7.4.26** (18 Nov 2021) **Core:** * Fixed bug php#81518 (Header injection via default_mimetype / default_charset). (cmb) **Date:** * Fixed bug php…
An update for redis is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of …
An update for redis is now available for Red Hat OpenStack Platform 10 (Newton). Red Hat Product Security has rated this update as having a security impact of …
An update for cluster-network-operator-container, cluster-version-operator-container, elasticsearch-operator-container, logging-kibana6-container, and ose-clus…
asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, b…
Andres Freund found an issue in the PostgreSQL database system where an uncontrolled search path could allow users to run arbitrary SQL functions with elevated…
A security researcher earlier today publicly revealed details and proof-of-concept exploit code for an unpatched, critical zero-day remote code execution vulne…
An update for Debezium PostgreSQL connector is now available for Red Hat Integration. Red Hat Product Security has rated this update as having a security impac…
**RELEASE 1.4.6** - Installer: Fix regression in SMTP test section (#7417) ---- **RELEASE 1.4.5** - Fix bug in extracting required plugins from composer.json t…
**MariaDB 10.4.13 , Galera 26.4.4 , MariaDB CONC/C 3.1.8** Release notes: https://mariadb.com/kb/en/mariadb-10413-release-notes/ https://mariadb.com/kb/en/mari…