USN-6968-3: PostgreSQL vulnerability
USN-6968-1 fixed CVE-2024-7348 in PostgreSQL-12, PostgreSQL-14, and PostgreSQL-16. This update provides the corresponding updates for PostgreSQL-9.3 in Ubuntu 14.04 LTS and PostgreSQL-10 in Ubuntu 18.04 LTS. Original advisory details: Noah Misch discovered that PostgreSQL incorrectly handled certain SQL objects. An attacker could possibly use this issue to execute arbitrary SQL functions as the superuser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6968-3?
The severity of USN-6968-3 is considered high due to the potential for exploitation in affected PostgreSQL versions.
How do I fix USN-6968-3?
To fix USN-6968-3, update PostgreSQL to the recommended version 10.23-0ubuntu0.18.04.2+esm2 for Ubuntu 18.04 and 9.3.24-0ubuntu0.14.04+esm1 for Ubuntu 14.04.
Which software is affected by USN-6968-3?
USN-6968-3 affects PostgreSQL-9.3 in Ubuntu 14.04 LTS and PostgreSQL-10 in Ubuntu 18.04 LTS.
What versions of PostgreSQL are updated in USN-6968-3?
USN-6968-3 updates PostgreSQL versions 9.3 and 10 to address the vulnerability.
Is there any potential impact of USN-6968-3?
The potential impact of USN-6968-3 includes unauthorized access to database systems due to the identified vulnerability.