UBUNTU-CVE-2025-49146

Source
https://ubuntu.com/security/CVE-2025-49146
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-49146.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2025-49146
Related
Published
2025-06-11T15:15:00Z
Modified
2025-06-13T12:43:28Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
[none]
Details

pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.

References

Affected packages

Ubuntu:Pro:14.04:LTS / libpgjava

Package

Name
libpgjava
Purl
pkg:deb/ubuntu/libpgjava@9.2-1002-1?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

9.*

9.2-1002-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / libpgjava

Package

Name
libpgjava
Purl
pkg:deb/ubuntu/libpgjava@9.2-1002-1?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

9.*

9.2-1002-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / libpgjava

Package

Name
libpgjava
Purl
pkg:deb/ubuntu/libpgjava@9.4.1212-1ubuntu0.1~esm1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

9.*

9.4.1212-1
9.4.1212-1ubuntu0.1~esm1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:20.04:LTS / libpgjava

Package

Name
libpgjava
Purl
pkg:deb/ubuntu/libpgjava@42.2.10-1ubuntu0.1~esm1?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

42.*

42.2.6-1
42.2.8-1
42.2.9-1
42.2.10-1
42.2.10-1ubuntu0.1~esm1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / libpgjava

Package

Name
libpgjava
Purl
pkg:deb/ubuntu/libpgjava@42.3.3-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

42.*

42.2.23-1
42.2.24-1
42.3.1-1
42.3.2-1
42.3.3-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / libpgjava

Package

Name
libpgjava
Purl
pkg:deb/ubuntu/libpgjava@42.7.3-1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

42.*

42.7.2-1
42.7.3-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / libpgjava

Package

Name
libpgjava
Purl
pkg:deb/ubuntu/libpgjava@42.7.2-1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

42.*

42.5.4-1
42.6.0-2
42.7.0-1
42.7.1-1
42.7.2-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:25.04 / libpgjava

Package

Name
libpgjava
Purl
pkg:deb/ubuntu/libpgjava@42.7.5-1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

42.*

42.7.3-1
42.7.3-2
42.7.5-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}