USN-3479-1
Dashboard / Vulnerabilities / USN-3479-1
USN-3479-1
Summary: postgresql-9.3, postgresql-9.5, postgresql-9.6 vulnerabilities
Details: David Rowley discovered that PostgreSQL incorrectly handled memory when processing certain JSON functions. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2017-15098) Dean Rasheed discovered that PostgreSQL incorrectly enforced SELECT privileges when processing INSERT ... ON CONFLICT DO UPDATE commands. A remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu 17.04 and Ubuntu 17.10.
References: https://ubuntu.com/security/notices/USN-3479-1, https://ubuntu.com/security/CVE-2017-15098, https://ubuntu.com/security/CVE-2017-15099
Affected packages
Package
Name: postgresql-9.3
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
