Bug 29655 - postgresql new security issues CVE-2021-23214 and CVE-2021-23222
Summary: postgresql new security issues CVE-2021-23214 and CVE-2021-23222
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks: 29681
  Show dependency treegraph
 
Reported: 2021-11-12 21:35 CET by David Walser
Modified: 2021-11-25 14:07 CET (History)
4 users (show)

See Also:
Source RPM: postgresql11-11.13-1.mga8.src.rpm, postgresql13-13.4-1.mga8.src.rpm
CVE: CVE-2021-23214, CVE-2021-23222
Status comment:


Attachments

Description David Walser 2021-11-12 21:35:40 CET
PostgreSQL has released new versions on November 11:
https://www.postgresql.org/about/news/postgresql-141-135-129-1114-1019-and-9624-released-2349/

The issues are fixed upstream in 11.14 and 13.5.

Cauldron and Mageia 8 are affected (postgresql13 and postgresql11).
David Walser 2021-11-12 21:35:50 CET

Whiteboard: (none) => MGA8TOO

Comment 1 Nicolas Salguero 2021-11-15 13:49:09 CET
Suggested advisory:
========================

The updated packages fix security vulnerabilities:

Server processes unencrypted bytes from man-in-the-middle. (CVE-2021-23214)

libpq processes unencrypted bytes from man-in-the-middle. (CVE-2021-23222)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23214
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23222
https://www.postgresql.org/about/news/postgresql-141-135-129-1114-1019-and-9624-released-2349/
========================

Updated packages in core/updates_testing:
========================
lib(64)pq5.11-11.14-1.mga8
lib(64)ecpg11_6-11.14-1.mga8
postgresql11-11.14-1.mga8
postgresql11-contrib-11.14-1.mga8
postgresql11-devel-11.14-1.mga8
postgresql11-docs-11.14-1.mga8
postgresql11-pl-11.14-1.mga8
postgresql11-plperl-11.14-1.mga8
postgresql11-plpgsql-11.14-1.mga8
postgresql11-plpython3-11.14-1.mga8
postgresql11-pltcl-11.14-1.mga8
postgresql11-server-11.14-1.mga8

lib(64)pq5-13.5-1.mga8
lib(64)ecpg13_6-13.5-1.mga8
postgresql13-13.5-1.mga8
postgresql13-contrib-13.5-1.mga8
postgresql13-devel-13.5-1.mga8
postgresql13-docs-13.5-1.mga8
postgresql13-pl-13.5-1.mga8
postgresql13-plperl-13.5-1.mga8
postgresql13-plpgsql-13.5-1.mga8
postgresql13-plpython3-13.5-1.mga8
postgresql13-pltcl-13.5-1.mga8
postgresql13-server-13.5-1.mga8

from SRPMS:
postgresql11-11.14-1.mga8.src.rpm
postgresql13-13.5-1.mga8.src.rpm

CVE: (none) => CVE-2021-23214, CVE-2021-23222
Status: NEW => ASSIGNED
CC: (none) => nicolas.salguero
Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8
Source RPM: postgresql11, postgresql13 => postgresql11-11.13-1.mga8.src.rpm, postgresql13-13.4-1.mga8.src.rpm
Assignee: bugsquad => qa-bugs

Comment 2 Herman Viaene 2021-11-18 16:06:16 CET
MGA8-64 Plasma on Lenovo B50
Installed first 11 version without problems
Replicated test from bug 29369 Comment 4 without problems
Removing version 11 and installing 13, to be continued.

CC: (none) => herman.viaene

Comment 3 Herman Viaene 2021-11-18 16:26:20 CET
Repeated test for version 13 with same OK results.
Marja Van Waes 2021-11-23 21:50:05 CET

Blocks: (none) => 29681

Comment 4 Dave Hodgins 2021-11-25 02:39:47 CET
With postgresql11, as reported in bug 29681 ...
php-pgsql-8.0.13-1.mga8.i586 (due to unsatisfied postgresql-libs[>= 13.5])

That's after installing the updateed postgresql11 from this report using qarepo.

Either php-pgsql has to be fixed to work with postgresql11, or as a workaround,
postgresql11 needs to add a provides that works with php-pgsql.

Adding feedback tag till a decision is reached.

Whiteboard: (none) => feedback
CC: (none) => davidwhodgins

Comment 5 David Walser 2021-11-25 03:03:28 CET
php-pgsql works with 13, not 11.  Also it's part of php, not postgresql.  We only have 11 packaged to support migration from Mageia 7.

Whiteboard: feedback => (none)

Comment 6 Dave Hodgins 2021-11-25 04:58:53 CET
In that case, validating the update. Both 11 and 13 install cleanly over the
prior versions and the service restarts ok.
Comment 7 Dave Hodgins 2021-11-25 05:03:01 CET
Actually validating.

Keywords: (none) => validated_update
Whiteboard: (none) => MGA8-64-OK
CC: (none) => sysadmin-bugs

Dave Hodgins 2021-11-25 05:27:55 CET

Keywords: (none) => advisory

Comment 8 Mageia Robot 2021-11-25 14:07:26 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0523.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.