USN-3390-1
Dashboard / Vulnerabilities / USN-3390-1
USN-3390-1
Summary: postgresql-9.3, postgresql-9.5, postgresql-9.6 vulnerabilities
Details: Ben de Graaff, Jelte Fennema, and Jeroen van der Ham discovered that PostgreSQL allowed the use of empty passwords in some authentication methods, contrary to expected behaviour. A remote attacker could use an empty password to authenticate to servers that were believed to have password login disabled. (CVE-2017-7546) Jeff Janes discovered that PostgreSQL incorrectly handled the pg_user_mappings catalog view. A remote attacker without server privileges could possibly use this issue to obtain certain passwords. (CVE-2017-7547) Chapman Flack discovered that PostgreSQL incorrectly handled lo_put() permissions. A remote attacker could possibly use this issue to change the data in a large object. (CVE-2017-7548)
References: https://ubuntu.com/security/notices/USN-3390-1, https://ubuntu.com/security/CVE-2017-7546, https://ubuntu.com/security/CVE-2017-7547, https://ubuntu.com/security/CVE-2017-7548
Affected packages
Package
Name: postgresql-9.3
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
