Security release for CVE-2022-41946 - Mailing list pgsql-jdbc

From Dave Cramer
Subject Security release for CVE-2022-41946
Date
Msg-id CADK3HHLhdL8-2u6E0oXfL_X1zsV00p6Q9Sw9Xa4VOAFV-zXbiQ@mail.gmail.com
Whole thread Raw
List pgsql-jdbc
Greetings,

There is an issue in the driver when setText, and setByte buffer the arguments to disk. File.createTempFile creates a file which can be read by any other user on the system. This has been fixed in versions 42.5.1, 42.4.3 42.3.8, 42.2.27.jre7.
Note there is no fix for 42.2.26.jre6. See the security advisory https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-562r-vg33-8x8h for work arounds.

Regards, 
Dave Cramer

pgsql-jdbc by date:

Previous
From: Dave Cramer
Date:
Subject: [pgjdbc/pgjdbc]
Next
From: Andy Fan
Date:
Subject: Would preparing internally during XAResource.end(xid, TMSUCCESS) works?