[USN-7358-1] PostgreSQL vulnerabilities

Hlib Korzhynskyy hlib.korzhynskyy at canonical.com
Wed Mar 19 14:08:26 UTC 2025


==========================================================================
Ubuntu Security Notice USN-7358-1
March 19, 2025

postgresql-9.5 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in PostgreSQL.

Software Description:
- postgresql-9.5: Object-relational SQL database

Details:

Wolfgang Walther discovered that PostgreSQL incorrectly tracked tables with
row security. A remote attacker could possibly use this issue to perform
forbidden reads and modifications. (CVE-2024-10976)

Jacob Champion discovered that PostgreSQL clients used untrusted server
error messages. An attacker that is able to intercept network
communications could possibly use this issue to inject error messages that
could be interpreted as valid query results. (CVE-2024-10977)

Tom Lane discovered that PostgreSQL incorrectly handled certain privilege
assignments. A remote attacker could possibly use this issue to view or
change different rows from those intended. (CVE-2024-10978)

Coby Abrams discovered that PostgreSQL incorrectly handled environment
variables. A remote attacker could possibly use this issue to execute
arbitrary code. (CVE-2024-10979)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS
   postgresql-9.5                  9.5.25-0ubuntu0.16.04.1+esm10
                                   Available with Ubuntu Pro
   postgresql-client-9.5           9.5.25-0ubuntu0.16.04.1+esm10
                                   Available with Ubuntu Pro

After a standard system update you need to restart PostgreSQL to make all
the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-7358-1
   CVE-2024-10976, CVE-2024-10977, CVE-2024-10978, CVE-2024-10979

-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <https://lists.ubuntu.com/archives/ubuntu-security-announce/attachments/20250319/d9916a94/attachment.sig>


More information about the ubuntu-security-announce mailing list