Bug 30295 - postgresql-jdbc new security issues CVE-2022-21724, CVE-2022-31197, CVE-2022-41946
Summary: postgresql-jdbc new security issues CVE-2022-21724, CVE-2022-31197, CVE-2022-...
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Java Stack Maintainers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-04-15 20:43 CEST by David Walser
Modified: 2024-01-12 09:47 CET (History)
1 user (show)

See Also:
Source RPM: postgresql-jdbc-42.3.0-1.mga9.src.rpm
CVE:
Status comment: Fixed upstream in 42.2.27, 42.3.8, 42.4.3, and 42.5.1


Attachments

Description David Walser 2022-04-15 20:43:50 CEST
Fedora has issued an advisory on April 14:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/BVEO7BEFXPBVHSPYL3YKQWZI6DYXQLFS/

The issue is fixed upstream in 42.2.5 and 42.3.2:
https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-v7wg-cpwc-24m4

Mageia 8 is also affected.
David Walser 2022-04-15 20:44:40 CEST

Whiteboard: (none) => MGA8TOO

Comment 1 David Walser 2022-04-15 20:52:44 CEST
Updated packaged checked into SVN.  Both updates failed on the build system:
http://pkgsubmit.mageia.org/uploads/failure/cauldron/core/release/20220415184723.luigiwalser.duvel.3927951/log/postgresql-jdbc-42.3.3-1.mga9/build.aarch64.0.20220415185154.log
http://pkgsubmit.mageia.org/uploads/failure/8/core/updates_testing/20220415184850.luigiwalser.duvel.3930116/log/postgresql-jdbc-42.2.25-1.mga8/build.aarch64.0.20220415185258.log

Advisory:
========================

Updated postgresql-jdbc packages fix security vulnerability:

A security hole was found in the jdbc driver for postgresql database while
doing security research. The system using the postgresql library will be
attacked when attacker control the jdbc url or properties. pgjdbc instantiates
plugin instances based on class names provided via
`authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`,
`sslfactory`, `sslpasswordcallback` connection properties. However, the driver
did not verify if the class implements the expected interface before
instantiating the class. This can lead to remote code execution loaded via
arbitrary classes. (CVE-2022-21724).

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21724
https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-v7wg-cpwc-24m4
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/BVEO7BEFXPBVHSPYL3YKQWZI6DYXQLFS/
========================

Updated packages in core/updates_testing:
========================
postgresql-jdbc-42.2.25-1.mga8
postgresql-jdbc-javadoc-42.2.25-1.mga8

from postgresql-jdbc-42.2.25-1.mga8.src.rpm

Assignee: bugsquad => java
Status comment: (none) => Updates checked into SVN but failed to build

Comment 2 David Walser 2022-08-04 19:05:06 CEST
SUSE has issued an advisory on August 3:
https://lists.suse.com/pipermail/sle-security-updates/2022-August/011762.html

The issue is fixed upstream in 42.3.3:
https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-673j-qm5f-xpv8

Mageia 8 is also affected.
Comment 4 David Walser 2022-10-06 15:13:17 CEST
Fedora has issued advisories on October 5:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/UTFE6SV33P5YYU2GNTQZQKQRVR3GYE4S/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/I6WHUADTZBBQLVHO4YG4XCWDGWBT4LRP/

The issues are fixed upstream in 42.2.26, 42.3.7, and 42.4.1:
https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-r38f-c4h4-hqq2

Summary: postgresql-jdbc new security issue CVE-2022-21724 => postgresql-jdbc new security issues CVE-2022-21724 and CVE-2022-31197
Status comment: Updates checked into SVN but failed to build => Fixed upstream in 42.2.26, 42.3.7, and 42.4.1

Comment 5 David Walser 2022-10-07 18:31:26 CEST
openSUSE has issued an advisory for the newest issue on October 6:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/X4D6FYYJXFISYRZVM6QVK6YMBG2KTXMC/
Comment 6 David Walser 2022-11-04 17:21:29 CET
postgresql-jdbc-42.5.0-1.mga9 uploaded for Cauldron.

Mageia 8 update still doesn't build:
http://pkgsubmit.mageia.org/uploads/failure/8/core/updates_testing/20221104160236.luigiwalser.duvel.1338727/log/postgresql-jdbc-42.2.26-1.mga8/build.aarch64.0.20221104160311.log

Version: Cauldron => 8
Whiteboard: MGA8TOO => (none)

Comment 7 David Walser 2023-01-18 00:32:14 CET
Fedora has issued an advisory on January 13:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/25TY2L3RMVNOC7VAHJEAO7PTT6M6JJAD/

The issue is fixed upstream in 42.2.7, 42.3.8, 42.4.3, and 42.5.1:
https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-562r-vg33-8x8h

Cauldron has been updated.

Status comment: Fixed upstream in 42.2.26, 42.3.7, and 42.4.1 => Fixed upstream in 42.2.27, 42.3.8, 42.4.3, and 42.5.1

David Walser 2023-01-20 17:30:22 CET

Summary: postgresql-jdbc new security issues CVE-2022-21724 and CVE-2022-31197 => postgresql-jdbc new security issues CVE-2022-21724, CVE-2022-31197, CVE-2022-41946

Comment 8 David Walser 2023-01-20 17:31:35 CET
(In reply to David Walser from comment #7)
> Fedora has issued an advisory on January 13:
> https://lists.fedoraproject.org/archives/list/package-announce@lists.
> fedoraproject.org/thread/25TY2L3RMVNOC7VAHJEAO7PTT6M6JJAD/
> 
> The issue is fixed upstream in 42.2.7, 42.3.8, 42.4.3, and 42.5.1:
> https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-562r-vg33-8x8h
> 
> Cauldron has been updated.

openSUSE has issued an advisory for this on January 19:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SYGPHYOMZE2VYMPEUXSVSZHF5VSAZAXU/
Comment 9 David Walser 2023-05-09 16:07:47 CEST
RedHat has issued an advisory for CVE-2022-41946 today (May 9):
https://access.redhat.com/errata/RHSA-2023:2378
Comment 10 Nicolas Salguero 2024-01-12 09:47:01 CET
Mageia 8 EOL

Status: NEW => RESOLVED
Resolution: (none) => OLD
CC: (none) => nicolas.salguero


Note You need to log in before you can comment on or make changes to this bug.