Several security issues were fixed in PostgreSQL.. =========================================================================Ubuntu Security Notice USN-5645-1 September 28, 2022 postgresql-9.5 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Several security issues were fixed in PostgreSQL. Software Description: - postgresql-9.5: Object-relational SQL database Details: Jacob Champion discovered that PostgreSQL incorrectly handled SSL certificate verification and encryption. A remote attacker could possibly use this issue to inject arbitrary SQL queries when a connection is first established. (CVE-2021-23214) Tom Lane discovered that PostgreSQL incorrect handled certain array subscripting calculations. An authenticated attacker could possibly use this issue to overwrite server memory and escalate privileges. (CVE-2021-32027) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: postgresql-9.5 9.5.25-0ubuntu0.16.04.1+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5645-1 CVE-2021-23214, CVE-2021-32027 . Notice regarding security updates for PostgreSQL vulnerabilities addressed in Ubuntu 16.04 ESM, encompassing severe SSL management issues.. PostgreSQL Security, Ubuntu 16.04, SQL Injection, Remote Access Exploit, Critical Flaws. . Severity: Critical. LinuxSecurity.com Team
The package glibc before version 2.21-1 has multiple issues that could be exploitable. . Arch Linux Security Advisory ASA-201502-8 ======================================== Severity: High Date : 2015-02-09 CVE-ID : CVE-2015-1472 CVE-2015-1473 Package : glibc Type : multiple issues Remote : possible (still under investigation) Link : https://wiki.archlinux.org/title/CVE Summary ====== The package glibc before version 2.21-1 has multiple issues that could be exploitable. Resolution ========= Upgrade to 2.21-1 # pacman -Syu "glibc> =2.21-1" The problems have been fixed upstream in version 2.21. Workaround ========= None. Description ========== glibc has multiple issues including heap- and stack overflows that could be exploitable. The heap- and stack-overflow is possible in the swscanf function. Impact ===== The issue is still under investigation. It's not clear if the issue is exploitable. In case of 'yes' this could result in various exploits in every software that uses glibc. This includes remote-code-execution or local exploits for gaining root access. References ========= https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2015-1472 https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2015-1473 https://sourceware.org/legacy-ml/libc-alpha/2015-02/msg00119.html . Debian highlights significant vulnerabilities in OpenSSL that could lead to serious breaches; users strongly encouraged to update to version 1.1.1k immediately.. Arch Linux Exploit, Glibc Security, Remote Code Access, Package Upgrade. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.