Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Debian DSA-5202-1 Urgent: OpenSSL TLS Protocol Vulnerabilities and Risks

debian
Calendar Grey July 31, 2022
Debian Logo
Critical security flaws found in the libpgjava PostgreSQL JDBC Driver necessitate prompt upgrades to ensure safety and performance.
Several security vulnerabilities have been found in libpgjava, the official PostgreSQL JDBC Driver

Summary

Several security vulnerabilities have been found in libpgjava, the official
PostgreSQL JDBC Driver.

CVE-2020-13692

An XML External Entity (XXE) weakness was found in PostgreSQL JDBC.

CVE-2022-21724

The JDBC driver did not verify if certain classes implemented the expected
interface before instantiating the class. This can lead to code execution
loaded via arbitrary classes.

CVE-2022-26520

An attacker (who controls the jdbc URL or properties) can call
java.util.logging.FileHandler to write to arbitrary files through the
loggerFile and loggerLevel connection properties.

For the oldstable distribution (buster), these problems have been fixed
in version 42.2.5-2+deb10u1.

For the stable distribution (bullseye), these problems have been fixed in
version 42.2.15-1+deb11u1.

We recommend that you upgrade your libpgjava packages.

For the detailed security status of libpgjava please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libpg...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: libpgjava
CVE ID: CVE-2020-13692 CVE-2022-21724 CVE-2022-26520

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here