Debian Security Advisory
DSA-5007-1 postgresql-13 -- security update
- Date Reported:
- 11 Nov 2021
- Affected Packages:
- postgresql-13
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2021-23214, CVE-2021-23222.
- More information:
-
Jacob Champion discovered two vulnerabilities in the PostgreSQL database system, which could result in man-in-the-middle attacks.
For the stable distribution (bullseye), these problems have been fixed in version 13.5-0+deb11u1.
We recommend that you upgrade your postgresql-13 packages.
For the detailed security status of postgresql-13 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/postgresql-13