> Debian pgextwlist SQL Injection Risk Fix DSA-6385-1 CVE-2023-39417
[DATE: 08/07/2026 21:26]
[LANGUAGE: EN]
Guillaume Winter discovered that pgextwlist, an extension for PostgreSQL implementing a whitelist mechanism for PostgreSQL extensions, was susceptible to SQL injection via crafted schema and user names. For the stable distribution (trixie), this problem has been fixed in version 1.19-1+deb13u1.