USN-5238-1: PostgreSQL JDBC Driver vulnerability
6 September 2022
PostgreSQL JDBC Driver could be made to crash or run programs if it received specially crafted input.
Releases
Packages
- libpgjava - Java database (JDBC) driver for PostgreSQL
Details
It was discovered that PostgreSQL JDBC Driver incorrectly handled certain
requests from external entities. A remote attacker could use this vulnerability
to cause a denial of service or possibly execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
-
libpostgresql-jdbc-java
-
42.2.10-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 18.04
-
libpostgresql-jdbc-java
-
9.4.1212-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.