当前位置:网站首页>云安全日报220623:红帽数据库管理系统发现执行任意代码漏洞,需要尽快升级
云安全日报220623:红帽数据库管理系统发现执行任意代码漏洞,需要尽快升级
2022-06-23 17:40:00 【TechWeb】
6月22日,红帽发布了安全更新,修复了红帽关系数据库管理系统PostgreSQL中发现的执行任意代码漏洞。以下是漏洞详情:
漏洞详情
来源:https://access.redhat.com/errata/RHSA-2022:5162
CVE-2022-1552 CVSS评分:8.8 严重程度:高
在 PostgreSQL 中发现了一个漏洞。当特权用户维护另一个用户的对象时,安全操作的努力不完整会出现问题。Autovacuum、REINDEX、CREATE INDEX、REFRESH MATERIALIZED VIEW、CLUSTER 和 pg_amcheck 命令在此过程中太晚或根本没有激活相关保护。此漏洞允许攻击者有权在至少一个模式中创建非临时对象,以在超级用户身份下执行任意SQL函数。
受影响产品和版本
Red Hat Enterprise Linux Server 7 x86_64
Red Hat Enterprise Linux Workstation 7 x86_64
Red Hat Enterprise Linux Desktop 7 x86_64
Red Hat Enterprise Linux for IBM z Systems 7 s390x
Red Hat Enterprise Linux for Power, big endian 7 ppc64
Red Hat Enterprise Linux for Scientific Computing 7 x86_64
Red Hat Enterprise Linux for Power, little endian 7 ppc64le
解决方案
RedHat官方已经 为 Red Hat Enterprise Linux 7 提供 postgresql 更新,如果 postgresql 服务正在运行,安装此更新后会自动重启。
有关如何应用此更新的详细信息,请参阅:
https://access.redhat.com/articles/11258
查看更多漏洞信息 以及升级请访问官网:
https://access.redhat.com/security/security-updates/#/security-advisories
边栏推荐
- Paper reading (55):dynamic multi robot task allocation under uncertainty and temporary constraints
- How to make good use of daily time to review efficiently?
- CV-背景-简介
- MySQL -- classic interview questions
- Know Chuangyu: content oriented, ai+ artificial empowerment
- 高级计网笔记(六)
- WIN11 系统所有快捷键说明
- QT implements a rule-based machinetranslation system course paper + assignment + project source code
- js25题目
- leetcode刷题:哈希表04 (两数之和)
猜你喜欢

基于QT实现的图形学绘制系统 文档+项目源码及可执行EXE文件+系统使用说明书

Paper reading (48):a Library of optimization algorithms for organizational design

【Unity】插件TextAnimator 新手使用说明

提高效率 Or 增加成本,开发人员应如何理解结对编程?

QT实现基于规则的机器翻译系统 课程论文+任务书+项目源码

Rancher2.6全新Monitoring快速入门

Regular expression use graph bed
![[Wwise] there is no sound problem after Wwise is embedded in unity and packaged](/img/70/4131671f5dfd36324cbe9bacea6ac4.png)
[Wwise] there is no sound problem after Wwise is embedded in unity and packaged

leetcode刷题:哈希表02 (两个数组的交集)

Self training multi sequence learning with transformer for weakly supervised video animation
随机推荐
[sword finger offer] 45 Arrange the array into the smallest number
基于FPGA的电磁超声脉冲压缩检测系统 论文+源文件
用软件可编程FPGA加速网络边缘的移动应用总结
leetcode刷题:哈希表05 (四数相加 II)
Asynchronous or thread pool
Leetcode: hash table 04 (sum of two numbers)
CV-背景-简介
微机原理第六章笔记整理
Dive into deep learning - 1. Introduction
Reading papers (51):integration of a holonic organizational control architecture and multiobjective
Implementing Domain Driven Design - using ABP framework - repository
测试
【Qt】第十章:数据库
3000帧动画图解MySQL为什么需要binlog、redo log和undo log
Paper reading (54):deepfool: a simple and accurate method to four deep neural networks
【 Huazhong University of Science and technology】 Data Sharing for retest of the initial Examination
Leetcode question brushing: hash table 01 (valid Letter ectopic words)
【华中科技大学】考研初试复试资料分享
org. apache. ibatis. binding. BindingException: Invalid bound statement (not found):...
The battlefield of live broadcast e-commerce is not in the live broadcast room