[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 3995-1] libpgjava security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3995-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                          Adrian Bunk
December 16, 2024                             https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : libpgjava
Version        : 42.2.15-1+deb11u2
CVE ID         : CVE-2022-31197 CVE-2022-41946 CVE-2024-1597
Debian Bug     : 1016662

Multiple vulnerabilities have been fixed in the PostgreSQL JDBC Driver.

CVE-2022-31197

    SQL Injection in ResultSet.refreshRow()

CVE-2022-41946

    temporary files can be read by other users

CVE-2024-1597

    SQL Injection via line comment generation

For Debian 11 bullseye, these problems have been fixed in version
42.2.15-1+deb11u2.

We recommend that you upgrade your libpgjava packages.

For the detailed security status of libpgjava please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libpgjava

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmdf7iMACgkQiNJCh6LY
mLGjLA/+MGKS2NFH/4bFN2f12+2K/ncanzgLXuQcmiZJ2+BwDfgZ4ja4J08YMACX
WXeld1qCfIhoUPISO4/4bHCOh1evc8gslQsRwRWfyklXT50ezemQ/muOpQjfA8Rm
YBrVdmoTYsJ6oixuHrK72Q/k1sKXREQ9J9ntsXQB+QAMJMccfNCwcUk3amwjsd/z
fcmRChXStyz0nUh28hvomtbB4CaaPB4+j8l/z57rFt1Brx/bWxILErvIgOdPCPQm
bjN7S2e0qONgaJHT/46QtOu53BQ/todtFMIjMFLFDDSU+1NQvjrEqzqHZC2S7Mls
wBgjh9HtVGCPoacsWjxzk2HuRwjoV3UcBRZ1MaPVImNgd6d0C0sDYVkpKmWjdnsc
31qwmofA1cjbJHGRiv1LKlRdQVPevuQpTtF87igOa8qVCJ4UNB5q8F4vtNV3065m
UFM3UVQgd42jXlMUYV2QcQvK/6VKVN2GMeQmJeA9338Hg6DAu2fusPyGVAJTXsg3
fNDFa+ari/Fi7wIayORJlrOTQfq+o/AE+ax90QdvhspM90PqZqg6icCgZPaRF15R
GtakppaZJSEvqdB3+TVgc6uqAGPBs3gTjNJ4RaJUxkaC+8wyb5RwfzLB3+GVz5iD
MEDQ+sBzjUZZWVsqI1Uz4JFydNNH9oDzJt1VH1cMnUkC949k8IY=
=6sqm
-----END PGP SIGNATURE-----


Reply to: