First published: Wed Apr 30 2025(Updated: )
USN-7315-1 fixed a vulnerability in PostgreSQL. This update provides the corresponding update for Ubuntu 18.04 LTS. Original advisory details: Stephen Fewer discovered that PostgreSQL incorrectly handled quoting syntax in certain scenarios. A remote attacker could possibly use this issue to perform SQL injection attacks.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/postgresql-10 | <10.23-0ubuntu0.18.04.2+esm3 | 10.23-0ubuntu0.18.04.2+esm3 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/postgresql-client-10 | <10.23-0ubuntu0.18.04.2+esm3 | 10.23-0ubuntu0.18.04.2+esm3 |
Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-7315-2 has been recognized as medium risk.
To fix USN-7315-2, you should update to the patched version 10.23-0ubuntu0.18.04.2+esm3 of PostgreSQL and postgresql-client-10.
USN-7315-2 affects PostgreSQL version 10 on Ubuntu 18.04 LTS systems.
The vulnerability in USN-7315-2 was discovered by Stephen Fewer.
USN-7315-2 addresses a vulnerability related to improper handling of quoting syntax in PostgreSQL.