Collected every two hours from specialised publications — each link leads to the original article.
According to recent reports, there have been instances of threat actors using malware called ''SkidMap'' to exploit vulnerable Redis systems.
As many as 196 hosts have been infected as part of an aggressive cloud campaign mounted by the TeamTNT group calledSilentbob."The botnet run by TeamTNT has set…
A new Golang-based malware dubbedGoBruteforcerhas been found targeting web servers running phpMyAdmin, MySQL, FTP, and Postgres to corral the devices into a bo…
An update for ovirt-ansible-collection, ovirt-engine, and postgresql-jdbc is now available for Red Hat Virtualization 4 Tools for Red Hat Enterprise Linux 8, R…
In yet another campaign targeting the Python Package Index (PyPI) repository, six malicious packages have been found deploying information stealers on develope…
pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `Prepa…
**MariaDB 10.5.18 & Galera 26.4.13** Release notes: https://mariadb.com/kb/en/mdb-10-5-18-rn/
An update for puppet-mysql is now available for Red Hat OpenStack Platform 13.0 (Queens), 16.1 (Train), 16.2 (Train) and 17.0 (Wallaby). Red Hat Product Securi…
It was discovered that there was a potential SQL injection vulnerability in libpgjava, a Java library for connecting to PostgreSQL databases.
Several security vulnerabilities have been found in libpgjava, the official PostgreSQL JDBC Driver. CVE-2020-13692
It was found that libpgjava, the official PostgreSQL JDBC Driver, would be vulnerable if an attacker controlled jdbc url or properties. The JDBC driver did not…
Potential SQL injection in QuerySet.annotate(), aggregate(), and extra() (CVE-2022-28346) Potential SQL injection via QuerySet.explain(**options) on PostgreSQL…
**MariaDB 10.5.15** Release notes: https://mariadb.com/kb/en/mariadb-10515-release-notes/
Emmet Leahy reported that libphp-adodb, a PHP database abstraction layer library, allows to inject values into a PostgreSQL connection string. Depending on how…
It was found that PgBouncer, a PostgreSQL connection pooler, was susceptible to an arbitrary SQL injection attack if a man-in-the-middle could inject data when…
Security hotfix release addressing a critical vulnerability in PostgreSQL connections (CVE-2021-3850) Additional fixes: Fix usage of get_magic_* functions #619…
It was found that in libphp-adodb, a PHP database abstraction layer library, an attacker can inject values into the PostgreSQL connection string by bypassing a…
Update to 1.16.1, per changes decribed at: http://www.pgbouncer.org/changelog.html#pgbouncer-116x Fixes multiple security vulnerabilities related to PostgreSQL…
The regression of postgresql-9.6-postgis-2.3-scripts being empty in 2.3.1+dfsg-2+deb9u1 has been fixed. For Debian 9 stretch, this problem has been fixed in ve…
In PostGIS, which adds support for geographic objects to the PostgreSQL database, denial of service via crafted ST_AsX3D function input was fixed.
**Version 4.4.35** (2021-11-24) * security **CVE-2021-41270** [Serializer] Use single quote to escape formulas (jderusse) * bug #44232 [Cache] fix connecting t…
**Version 4.4.35** (2021-11-24) * security **CVE-2021-41270** [Serializer] Use single quote to escape formulas (jderusse) * bug #44232 [Cache] fix connecting t…
**PHP version 7.4.26** (18 Nov 2021) **Core:** * Fixed bug php#81518 (Header injection via default_mimetype / default_charset). (cmb) **Date:** * Fixed bug php…
**PHP version 7.4.26** (18 Nov 2021) **Core:** * Fixed bug php#81518 (Header injection via default_mimetype / default_charset). (cmb) **Date:** * Fixed bug php…