INFSA-2024:10787: postgresql:15 security update

Information about definition

Identificator: INFSA-2024:10787

Type: security

Release date: 2025-07-14 19:30:11 UTC

Information about package

PostgreSQL is an advanced object-relational database management system (DBMS).

Vulnerabilities description

  • CVE-2024-10976

    A flaw was found in PostgreSQL. This vulnerability allows incorrect row-level security policies to be applied via subqueries, WITH queries, security invoker views, or SQL-language functions that reference tables with row-level security policies. This issue arises when a query is planned under one role and executed under another, potentially leading to unauthorized reads or modifications of data.

  • CVE-2024-10978

    A flaw was found in PostgreSQL. This vulnerability allows a less-privileged application user to view or change unintended rows using SET ROLE, SET SESSION AUTHORIZATION, or equivalent features resulting in loss of confidentiality integrity and availability.

  • CVE-2024-10979

    A flaw was found in PostgreSQL PL/Perl. This vulnerability allows an unprivileged database user to change sensitive process environment variables (e.g., PATH) via incorrect control of environment variables.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 4.2 no information
no information 4.2 no information
no information 8.8 no information
Critical, important, moderate, low

Updated packages