Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Ubuntu 16.04 ESM, USN-5676-1 Critical: PostgreSQL Command Exec Threat

Ubuntu Large Esm H500
PostgreSQL could be made to execute commands as the superuser.
=========================================================================Ubuntu Security Notice USN-5676-1
October 13, 2022

postgresql-9.5 vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM

Summary:

PostgreSQL could be made to execute commands as the superuser.

Software Description:
- postgresql-9.5: Object-relational SQL database

Details:

Alexander Lakhin discovered that PostgreSQL incorrectly handled the
security restricted operation sandbox when a privileged user is 
maintaining another user’s objects. An attacker having permission to 
create non-temp objects can use this issue to execute arbitrary commands 
as the superuser.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
   postgresql-9.5                  9.5.25-0ubuntu0.16.04.1+esm2

After a standard system update you need to restart PostgreSQL to
make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-5676-1
   CVE-2022-1552

Ubuntu 16.04 ESM, USN-5676-1 Critical: PostgreSQL Command Exec Threat

ubuntu
Calendar Grey October 13, 2022
Dist Ubuntu Esm H88
An alert regarding PostgreSQL on Ubuntu outlines a vulnerability that permits malicious entities to run commands with superuser privileges, emphasizing the need for immediate software patches.
PostgreSQL could be made to execute commands as the superuser.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: postgresql-9.5 9.5.25-0ubuntu0.16.04.1+esm2 After a standard system update you need to restart PostgreSQL to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5676-1

CVE-2022-1552

Severity
critical
Lowest
Low
Medium
High
Critical

October 13, 2022

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here