Ubuntu Security Update USN-7908-1: PostgreSQL vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,787
Reaction score
74
Credits
-1,257
Jelte Fennema-Nio discovered that the PostgreSQL CREATE STATISTICS command did not correctly check for schema CREATE privileges. An authenticated attacker could possibly use this issue to create a denial of service against other CREATE STATISTICS users. (CVE-2025-12817) Aleksey Solovev discovered that the PostgreSQL libpq client library incorrectly handled certain memory operations. A remote attacker could possibly use this issue to cause libpq to crash, resulting in a denial of service. (CVE-2025-12818)

Continue reading...
 


Follow Linux.org

Members online


Top