ubuntu · CVE-2017-7485

Quick triage

Priority: low Published: 2017-05-12 19:29:00 UTC Updated: 2025-08-25 22:37:43 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-7485 low priority: Ubuntu including 4 source packages (postgresql-9.1, postgresql-9.3, postgresql-9.5, postgresql-9.6), 24 status rows across 6 suites (artful, trusty, upstream, xenial, yakkety, zesty): DNE 15, released 5, not-affected 2, ignored 1, needed 1.

Description:

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.

cvelogic Threat Intelligence