USN-3479-1: PostgreSQL vulnerabilities
USN-3479-1: PostgreSQL vulnerabilities Ubuntu Security Notice USN-3479-1 14th November, 2017 postgresql-9.3, postgresql-9.5, postgresql-9.6 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in PostgreSQL. Software description postgresql-9.3 – Object-relational SQL database postgresql-9.5 – Object-relational SQL database postgresql-9.6 – Object-relational SQL database Details David Rowley discovered that PostgreSQL incorrectly handled memory whenprocessing certain JSON functions. A remote attacker could possibly usethis issue to obtain sensitive information. (CVE-2017-15098) Dean Rasheed discovered that PostgreSQL incorrectly enforced SELECTprivileges when processing INSERT … ON CONFLICT DO UPDATE commands. Aremote attacker could possibly use this issue to obtain sensitiveinformation. This issue only affected Ubuntu 16.04 LTS, Ubuntu 17.04 andUbuntu 17.10. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu [ more… ]