{"id":"USN-6968-3","summary":"postgresql-10, postgresql-9.3 vulnerability","details":"USN-6968-1 fixed CVE-2024-7348 in PostgreSQL-12, PostgreSQL-14, and\nPostgreSQL-16.\n\nThis update provides the corresponding updates for PostgreSQL-9.3 in\nUbuntu 14.04 LTS and PostgreSQL-10 in Ubuntu 18.04 LTS.\n\nOriginal advisory details:\n\n Noah Misch discovered that PostgreSQL incorrectly handled certain\n SQL objects. An attacker could possibly use this issue to execute\n arbitrary SQL functions as the superuser.\n","modified":"2026-04-22T10:50:58.166420Z","published":"2024-10-14T14:00:19Z","related":["UBUNTU-CVE-2024-7348"],"upstream":["CVE-2024-7348","UBUNTU-CVE-2024-7348"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6968-3"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-7348"}],"affected":[{"package":{"name":"postgresql-9.3","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/postgresql-9.3@9.3.24-0ubuntu0.14.04+esm1?arch=source&distro=trusty/esm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.3.24-0ubuntu0.14.04+esm1"}]}],"versions":["9.3.1-1","9.3.2-1","9.3.2-1ubuntu1","9.3.2-1ubuntu2","9.3.3-1","9.3.3-1bzr1","9.3.3-1bzr2","9.3.4-1","9.3.5-0ubuntu0.14.04.1","9.3.6-0ubuntu0.14.04","9.3.7-0ubuntu0.14.04","9.3.8-0ubuntu0.4.04","9.3.9-0ubuntu0.14.04","9.3.10-0ubuntu0.14.04","9.3.11-0ubuntu0.14.04","9.3.12-0ubuntu0.14.04","9.3.13-0ubuntu0.14.04","9.3.14-0ubuntu0.14.04","9.3.15-0ubuntu0.14.04","9.3.16-0ubuntu0.14.04","9.3.17-0ubuntu0.14.04","9.3.18-0ubuntu0.14.04.1","9.3.19-0ubuntu0.14.04","9.3.20-0ubuntu0.14.04","9.3.21-0ubuntu0.14.04","9.3.22-0ubuntu0.14.04","9.3.23-0ubuntu0.14.04","9.3.24-0ubuntu0.14.04"],"ecosystem_specific":{"binaries":[{"binary_name":"libecpg-compat3","binary_version":"9.3.24-0ubuntu0.14.04+esm1"},{"binary_name":"libecpg6","binary_version":"9.3.24-0ubuntu0.14.04+esm1"},{"binary_name":"libpgtypes3","binary_version":"9.3.24-0ubuntu0.14.04+esm1"},{"binary_name":"libpq5","binary_version":"9.3.24-0ubuntu0.14.04+esm1"},{"binary_name":"postgresql-9.3","binary_version":"9.3.24-0ubuntu0.14.04+esm1"},{"binary_name":"postgresql-client-9.3","binary_version":"9.3.24-0ubuntu0.14.04+esm1"},{"binary_name":"postgresql-contrib-9.3","binary_version":"9.3.24-0ubuntu0.14.04+esm1"},{"binary_name":"postgresql-doc-9.3","binary_version":"9.3.24-0ubuntu0.14.04+esm1"},{"binary_name":"postgresql-plperl-9.3","binary_version":"9.3.24-0ubuntu0.14.04+esm1"},{"binary_name":"postgresql-plpython-9.3","binary_version":"9.3.24-0ubuntu0.14.04+esm1"},{"binary_name":"postgresql-plpython3-9.3","binary_version":"9.3.24-0ubuntu0.14.04+esm1"},{"binary_name":"postgresql-pltcl-9.3","binary_version":"9.3.24-0ubuntu0.14.04+esm1"},{"binary_name":"postgresql-server-dev-9.3","binary_version":"9.3.24-0ubuntu0.14.04+esm1"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:14.04:LTS","cves":[{"id":"CVE-2024-7348","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6968-3.json"}},{"package":{"name":"postgresql-10","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/postgresql-10@10.23-0ubuntu0.18.04.2+esm2?arch=source&distro=esm-infra/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.23-0ubuntu0.18.04.2+esm2"}]}],"versions":["10.1-1","10.1-2","10.2-1","10.3-1","10.4-0ubuntu0.18.04","10.5-0ubuntu0.18.04","10.6-0ubuntu0.18.04.1","10.7-0ubuntu0.18.04.1","10.8-0ubuntu0.18.04.1","10.9-0ubuntu0.18.04.1","10.10-0ubuntu0.18.04.1","10.12-0ubuntu0.18.04.1","10.14-0ubuntu0.18.04.1","10.15-0ubuntu0.18.04.1","10.16-0ubuntu0.18.04.1","10.17-0ubuntu0.18.04.1","10.18-0ubuntu0.18.04.1","10.19-0ubuntu0.18.04.1","10.20-0ubuntu0.18.04.1","10.21-0ubuntu0.18.04.1","10.22-0ubuntu0.18.04.1","10.23-0ubuntu0.18.04.1","10.23-0ubuntu0.18.04.2","10.23-0ubuntu0.18.04.2+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"libecpg-compat3","binary_version":"10.23-0ubuntu0.18.04.2+esm2"},{"binary_name":"libecpg6","binary_version":"10.23-0ubuntu0.18.04.2+esm2"},{"binary_name":"libpgtypes3","binary_version":"10.23-0ubuntu0.18.04.2+esm2"},{"binary_name":"libpq5","binary_version":"10.23-0ubuntu0.18.04.2+esm2"},{"binary_name":"postgresql-10","binary_version":"10.23-0ubuntu0.18.04.2+esm2"},{"binary_name":"postgresql-client-10","binary_version":"10.23-0ubuntu0.18.04.2+esm2"},{"binary_name":"postgresql-doc-10","binary_version":"10.23-0ubuntu0.18.04.2+esm2"},{"binary_name":"postgresql-plperl-10","binary_version":"10.23-0ubuntu0.18.04.2+esm2"},{"binary_name":"postgresql-plpython-10","binary_version":"10.23-0ubuntu0.18.04.2+esm2"},{"binary_name":"postgresql-plpython3-10","binary_version":"10.23-0ubuntu0.18.04.2+esm2"},{"binary_name":"postgresql-pltcl-10","binary_version":"10.23-0ubuntu0.18.04.2+esm2"},{"binary_name":"postgresql-server-dev-10","binary_version":"10.23-0ubuntu0.18.04.2+esm2"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[{"id":"CVE-2024-7348","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6968-3.json"}}],"schema_version":"1.7.5"}