Wednesday, March 19, 2025

[USN-7358-1] PostgreSQL vulnerabilities

-----BEGIN PGP SIGNATURE-----

wsF5BAABCAAjFiEELOLXZEFYQHcSWEHiyfW2m9Ldu6sFAmfaz9sFAwAAAAAACgkQyfW2m9Ldu6sK
5hAArr86GfUsoIB9C6FV/67CA8/U/kQ3VvBHzJn+BAtQhRF9BMirjr72msRBZihZ9laOQJY0ijm/
kZLnUDu/Iqy+FHLwtTKPh4MxWCQa39hCpmMdUJv/JTuksPEhMw+yJQMDbPTd8jwI16ZReP29oE1b
vGEqrrIzcIOX17wss4drp4Nys0Y96+1O5jzIUE8wUy7H44tikUA0XAQcCXJgfvNg3jyGXXkerJ8t
YxpotGp6eC7fXaZrDbceNgmFE2kCmEt4NDZccSfkOJyRf3LDEBE0LKwP5BVRJEHgMKrNW/QcdtFQ
jS3ZSsMNCSoGXzKy+zn2c7rG2BErrEKw7PVbT26oI29WvtfB86MDFQMqx9D7wS1Dn5RKHPrg2vW0
hO951e9Q28oadHD3dE2fn7His0MbuU+OZzyjN1qraFd3PrTBByseJvZi/+p6bHxfUxr88Aon1hlY
An5jtL8x+JA0S3E6DgKDabg9xv1LtYoNwu/1j17vxTGf1hn6K8m/iYaco7iO0znpNHv9BD2RqaOy
ryDyebzYS65EiHjEJnp0eNwtoHQ0NEXru4G7PlTLBvTH1eOfIDZS2gpjDapnm3AUip8eNn4EaKMs
Z56dB/81FZX1JnnAjrTLuMhOIzsrSE6mNgBdDt2azHyCpERXHxyx2lbwv8w+DsKa5ENm1bxXQves
dLo=
=laud
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7358-1
March 19, 2025

postgresql-9.5 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in PostgreSQL.

Software Description:
- postgresql-9.5: Object-relational SQL database

Details:

Wolfgang Walther discovered that PostgreSQL incorrectly tracked tables with
row security. A remote attacker could possibly use this issue to perform
forbidden reads and modifications. (CVE-2024-10976)

Jacob Champion discovered that PostgreSQL clients used untrusted server
error messages. An attacker that is able to intercept network
communications could possibly use this issue to inject error messages that
could be interpreted as valid query results. (CVE-2024-10977)

Tom Lane discovered that PostgreSQL incorrectly handled certain privilege
assignments. A remote attacker could possibly use this issue to view or
change different rows from those intended. (CVE-2024-10978)

Coby Abrams discovered that PostgreSQL incorrectly handled environment
variables. A remote attacker could possibly use this issue to execute
arbitrary code. (CVE-2024-10979)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS
  postgresql-9.5                  9.5.25-0ubuntu0.16.04.1+esm10
                                  Available with Ubuntu Pro
  postgresql-client-9.5           9.5.25-0ubuntu0.16.04.1+esm10
                                  Available with Ubuntu Pro

After a standard system update you need to restart PostgreSQL to make all
the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-7358-1
  CVE-2024-10976, CVE-2024-10977, CVE-2024-10978, CVE-2024-10979

No comments:

Post a Comment