Lucene search

K
ubuntuUbuntuUSN-5765-1
HistoryDec 07, 2022 - 12:00 a.m.

PostgreSQL vulnerability

2022-12-0700:00:00
ubuntu.com
26
postgresql
ssl certificate
ubuntu 16.04
esm
sql injection
encryption

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.7%

Releases

  • Ubuntu 16.04 ESM

Packages

  • postgresql-9.5 - Object-relational SQL database

Details

Jacob Champion discovered that PostgreSQL incorrectly handled SSL
certificate verification and encryption. A remote attacker could possibly
use this issue to inject arbitrary SQL queries when a connection is first
established.

OSVersionArchitecturePackageVersionFilename
Ubuntu16.04noarchpostgresql-9.5< 9.5.25-0ubuntu0.16.04.1+esm3UNKNOWN
Ubuntu16.04noarchlibecpg-compat3< 9.5.25-0ubuntu0.16.04.1UNKNOWN
Ubuntu16.04noarchlibecpg-compat3-dbgsym< 9.5.25-0ubuntu0.16.04.1UNKNOWN
Ubuntu16.04noarchlibecpg-dev< 9.5.25-0ubuntu0.16.04.1UNKNOWN
Ubuntu16.04noarchlibecpg-dev-dbgsym< 9.5.25-0ubuntu0.16.04.1UNKNOWN
Ubuntu16.04noarchlibecpg6< 9.5.25-0ubuntu0.16.04.1UNKNOWN
Ubuntu16.04noarchlibecpg6-dbgsym< 9.5.25-0ubuntu0.16.04.1UNKNOWN
Ubuntu16.04noarchlibpgtypes3< 9.5.25-0ubuntu0.16.04.1UNKNOWN
Ubuntu16.04noarchlibpgtypes3-dbgsym< 9.5.25-0ubuntu0.16.04.1UNKNOWN
Ubuntu16.04noarchlibpq-dev< 9.5.25-0ubuntu0.16.04.1UNKNOWN
Rows per page:
1-10 of 311

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.7%