========================================================================== Ubuntu Security Notice USN-5645-1 September 28, 2022 postgresql-9.5 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Several security issues were fixed in PostgreSQL. Software Description: - postgresql-9.5: Object-relational SQL database Details: Jacob Champion discovered that PostgreSQL incorrectly handled SSL certificate verification and encryption. A remote attacker could possibly use this issue to inject arbitrary SQL queries when a connection is first established. (CVE-2021-23214) Tom Lane discovered that PostgreSQL incorrect handled certain array subscripting calculations. An authenticated attacker could possibly use this issue to overwrite server memory and escalate privileges. (CVE-2021-32027) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: postgresql-9.5 9.5.25-0ubuntu0.16.04.1+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5645-1 CVE-2021-23214, CVE-2021-32027