View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2024-7348 severity important: SUSE including 631 source package names (0.3.32-3.4:libpq5-16.4-150600.16.5.1, 15-30.1:libpq5-16.4-150200.5.16.1, …), 1806 product×package rows across 71 product lines (Container containers/open-webui, Container private-registry/harbor-db, … (71 product lines)): Fixed 1219, Known Not Affected 252, Known Affected 231, Will Not Fix 104.
Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected.