Debian Security Advisory
DSA-4622-1 postgresql-9.6 -- security update
- Date Reported:
- 13 Feb 2020
- Affected Packages:
- postgresql-9.6
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2020-1720.
- More information:
-
Tom Lane discovered that
ALTER ... DEPENDS ON EXTENSION
sub commands in the PostgreSQL database did not perform authorisation checks.For the oldstable distribution (stretch), this problem has been fixed in version 9.6.17-0+deb9u1.
We recommend that you upgrade your postgresql-9.6 packages.
For the detailed security status of postgresql-9.6 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/postgresql-9.6