当前位置:网站首页>Cloud security daily 220623: the red hat database management system has found an arbitrary code execution vulnerability and needs to be upgraded as soon as possible
Cloud security daily 220623: the red hat database management system has found an arbitrary code execution vulnerability and needs to be upgraded as soon as possible
2022-06-23 18:50:00 【TechWeb】
6 month 22 Japan , Red hat has released a security update , Fixed the red hat relational database management system PostgreSQL Arbitrary code execution vulnerability found in . Here are the details of the vulnerability :
Vulnerability Details
source :https://access.redhat.com/errata/RHSA-2022:5162
CVE-2022-1552 CVSS score :8.8 severity : high
stay PostgreSQL A hole was found in . When a privileged user maintains another user's object , Incomplete efforts for safe operation will cause problems .Autovacuum、REINDEX、CREATE INDEX、REFRESH MATERIALIZED VIEW、CLUSTER and pg_amcheck The command is too late in the process or the relevant protection is not activated at all . This vulnerability allows an attacker to create non temporary objects in at least one mode , To execute any... As superuser SQL function .
Affected products and versions
Red Hat Enterprise Linux Server 7 x86_64
Red Hat Enterprise Linux Workstation 7 x86_64
Red Hat Enterprise Linux Desktop 7 x86_64
Red Hat Enterprise Linux for IBM z Systems 7 s390x
Red Hat Enterprise Linux for Power, big endian 7 ppc64
Red Hat Enterprise Linux for Scientific Computing 7 x86_64
Red Hat Enterprise Linux for Power, little endian 7 ppc64le
Solution
RedHat Official by Red Hat Enterprise Linux 7 Provide postgresql to update , If postgresql Service is running , Automatically restart after installing this update .
For more information on how to apply this update , see also :
https://access.redhat.com/articles/11258
View more vulnerability information And upgrade, please visit the official website :
https://access.redhat.com/security/security-updates/#/security-advisories
边栏推荐
- mysql -- 经典面试题
- Shell process control - 39. Special process control statements
- 涂鸦智能通过聆讯:拟回归香港上市 腾讯是重要股东
- Five star certification! Know that Chuangyu has passed the evaluation of the content audit service system of China Academy of Communications
- 【Qt】第十章:数据库
- TimerTasks笔记
- test
- 在Microsoft Exchange Server 2007中安装SSL证书的教程
- 外卖江湖格局将变,美团“大哥”不好当
- 杰理之添加定时器中断【篇】
猜你喜欢

NetCF总结

Shell process control - 39. Special process control statements

亚香香料深交所上市:市值40亿 鼎龙博晖与涌耀投资是股东
![【NOI2014】15. Difficult to get up syndrome [binary]](/img/3a/12e9b2566d3ca3330a3cc6c5eaf135.png)
【NOI2014】15. Difficult to get up syndrome [binary]

涂鸦智能通过聆讯:拟回归香港上市 腾讯是重要股东

Leetcode: hash table 06 (ransom letter)

Basic knowledge of penetration test

博睿数据出席阿里云可观测技术峰会,数字体验管理驱动可持续发展

8、AI医生案例

Will programmers become very professional in the future?
随机推荐
渗透测试基础,初识渗透测试
Machine learning jobs
golang set type implementation
STM32 (VIII) -- PWM output
Will programmers become very professional in the future?
NetSeer:可编程数据平面的流事件遥测笔记
杰理之.强制升级【篇】
物流服务与管理主要学什么
2022年升降机司机考试题模拟考试平台操作
【NOI2014】15.起床困難綜合症【二進制】
用户分析-AARRR模型(海盗模型)
从零开发小程序和公众号【第二期】
高级计网笔记(五)
杰理之串口通信 串口接收 IO 需要设置数字功能【篇】
vPROM笔记
随机过程——马尔科夫链
Leetcode: hash table 06 (ransom letter)
[QT] Chapter 10: Database
用软件可编程FPGA加速网络边缘的移动应用总结
Obtain equipment information