Debian dsa-6438 : libecpg-compat3 - security update

high Nessus Plugin ID 335238

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 13 host has packages installed that are affected by multiple vulnerabilities as referenced in the dsa-6438 advisory.

- ------------------------------------------------------------------------- Debian Security Advisory DSA-6438-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff August 13, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : postgresql-17 CVE ID : CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 CVE-2026-6473 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-14681 CVE-2026-15741 CVE-2026-15742 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024 CVE-2026-18408 CVE-2026-19385

Multiple security issues were discovered in PostgreSQL, which may result in execution of arbitrary code, incorrect authentication, information disclosure, or privilege escalation.

The upstream fix to address CVE-2026-6471 requires additional changes to the configuration if some extensions are used. This affects the postgresql-17-wal2json, postgresql-17-squeeze, postgresql-17-pg-rewrite and postgresql-17-decoderbufs extensions included in Debian.
Quoting from the changelog:

| Restrict logical decoding output plugins to the set specified by | a new server parameter `output_plugin_libraries` (Jacob | Champion) | Previously, a replication user could select any loadable library | | Restrict logical decoding output plugins to the set specified by | a new server parameter `output_plugin_libraries` (Jacob | Champion) | Previously, a replication user could select any loadable library | for logical decoding, allowing exploits of various sorts. To | allow locking this down without breaking setups that worked | before, introduce a whitelist of allowed output plugins.
| | By default, only the output plugins shipped as part of | PostgreSQL (`pgoutput` and `test_decoding`) are included in |`output_plugin_libraries`. Installations that rely on other | output plugins must add them after updating the server, for | example | | output_plugin_libraries = 'pgoutput, test_decoding, my_trusted_decoder'

For the stable distribution (trixie), these problems have been fixed in version 17.11-0+deb13u1.

We recommend that you upgrade your postgresql-17 packages.

For the detailed security status of postgresql-17 please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/postgresql-17

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/

Mailing list: [email protected]

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the libecpg-compat3 packages.

See Also

https://packages.debian.org/source/trixie/postgresql-17

https://security-tracker.debian.org/tracker/CVE-2026-14662

https://security-tracker.debian.org/tracker/CVE-2026-14663

https://security-tracker.debian.org/tracker/CVE-2026-14664

https://security-tracker.debian.org/tracker/CVE-2026-14666

https://security-tracker.debian.org/tracker/CVE-2026-14668

https://security-tracker.debian.org/tracker/CVE-2026-14669

https://security-tracker.debian.org/tracker/CVE-2026-14670

https://security-tracker.debian.org/tracker/CVE-2026-14671

https://security-tracker.debian.org/tracker/CVE-2026-14672

https://security-tracker.debian.org/tracker/CVE-2026-14673

https://security-tracker.debian.org/tracker/CVE-2026-14677

https://security-tracker.debian.org/tracker/CVE-2026-14678

https://security-tracker.debian.org/tracker/CVE-2026-14679

https://security-tracker.debian.org/tracker/CVE-2026-14680

https://security-tracker.debian.org/tracker/CVE-2026-14681

https://security-tracker.debian.org/tracker/CVE-2026-15741

https://security-tracker.debian.org/tracker/CVE-2026-15742

https://security-tracker.debian.org/tracker/CVE-2026-16239

https://security-tracker.debian.org/tracker/CVE-2026-16241

https://security-tracker.debian.org/tracker/CVE-2026-18024

https://security-tracker.debian.org/tracker/CVE-2026-18408

https://security-tracker.debian.org/tracker/CVE-2026-19385

https://security-tracker.debian.org/tracker/CVE-2026-6464

https://security-tracker.debian.org/tracker/CVE-2026-6469

https://security-tracker.debian.org/tracker/CVE-2026-6470

https://security-tracker.debian.org/tracker/CVE-2026-6471

https://security-tracker.debian.org/tracker/CVE-2026-6473

http://www.nessus.org/u?348128da

Plugin Details

Severity: High

ID: 335238

File Name: debian_DSA-6438.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/13/2026

Updated: 8/13/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.15

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-18408

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-6473

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:13.0, p-cpe:/a:debian:debian_linux:libecpg-compat3, p-cpe:/a:debian:debian_linux:libecpg-dev, p-cpe:/a:debian:debian_linux:libecpg6, p-cpe:/a:debian:debian_linux:libpgtypes3, p-cpe:/a:debian:debian_linux:libpq-dev, p-cpe:/a:debian:debian_linux:libpq5, p-cpe:/a:debian:debian_linux:postgresql-17, p-cpe:/a:debian:debian_linux:postgresql-client-17, p-cpe:/a:debian:debian_linux:postgresql-doc-17, p-cpe:/a:debian:debian_linux:postgresql-plperl-17, p-cpe:/a:debian:debian_linux:postgresql-plpython3-17, p-cpe:/a:debian:debian_linux:postgresql-pltcl-17, p-cpe:/a:debian:debian_linux:postgresql-server-dev-17

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 8/13/2026

Vulnerability Publication Date: 5/14/2026

Reference Information

CVE: CVE-2026-14662, CVE-2026-14663, CVE-2026-14664, CVE-2026-14666, CVE-2026-14668, CVE-2026-14669, CVE-2026-14670, CVE-2026-14671, CVE-2026-14672, CVE-2026-14673, CVE-2026-14677, CVE-2026-14678, CVE-2026-14679, CVE-2026-14680, CVE-2026-14681, CVE-2026-15741, CVE-2026-15742, CVE-2026-16239, CVE-2026-16241, CVE-2026-18024, CVE-2026-18408, CVE-2026-19385, CVE-2026-6464, CVE-2026-6469, CVE-2026-6470, CVE-2026-6471, CVE-2026-6473