-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 09 Oct 2026 11:14:28 +0200 Source: libpgjava Architecture: source Version: 42.7.14-1 Distribution: unstable Urgency: medium Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Christoph Berg <myon@debian.org> Closes: 1150330 Changes: libpgjava (42.7.14-1) unstable; urgency=medium . * New upstream version 42.7.14. (Closes: #1150330) + CVE-2026-107315: versions 42.7.4 through 42.7.13 pad a value that is shorter than its declared length with bytes left in its send buffer instead of zeros, and the server stores those bytes as part of the value. The bytes are messages the driver sent earlier on the same connection: SQL text and parameter values of recent statements, which on a pooled connection can come from other requests. Each padded value can carry up to 8192 bytes of this traffic, or 16320 bytes on a connection with GSS encryption. The padding happens when an application declares a length larger than the data it supplies, through PreparedStatement.setObject with a ByteStreamWriter, CopyIn.writeToCopy, PGCopyOutputStream.write, LargeObject.write, or Blob.setBytes. The driver accepts these calls without an error. An attacker who can make the application store such a value and read it back can collect earlier traffic. Applications whose declared lengths always match their data are not affected. Versions 42.7.3 and earlier pad with zeros. + CVE-2026-107314: versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver then accepts any method the server asks for, including cleartext password authentication. A value without a method in it, such as requireAuth=, (a single comma), is affected the same way. An attacker positioned between the application and its server can ask for cleartext password authentication and receive the database password. A positive list such as requireAuth=scram-sha-256, and a partial exclusion such as requireAuth=!password,!md5, are enforced correctly. The property has no default value, so a deployment that does not set it is not affected. 42.7.14 fixes the problem: such a connection is refused with SQLState 08004, and a value without a method in it is rejected as invalid. Checksums-Sha1: 944da05a66bf5092fbe5345307a1aef2801681e9 2426 libpgjava_42.7.14-1.dsc 522aed9be110272187ff0b7b7e5d771acbf6e3a0 1224149 libpgjava_42.7.14.orig.tar.gz 98c9dda4625a12fac5174dce8a8a51037226d9ec 11764 libpgjava_42.7.14-1.debian.tar.xz Checksums-Sha256: c14c83a5486cf4da479ddab38f3e3b21ac9cdea8f4d97175e5e8a7cef5b566e8 2426 libpgjava_42.7.14-1.dsc 1f38e5e32f1e9b2200f6c0e7cce02d635d7bc14b35dff803a52e09cd666a16b9 1224149 libpgjava_42.7.14.orig.tar.gz 5a614a21193cf7ffdfdaf334433307d3628cb10beddc02bd292fc3eb76da26ed 11764 libpgjava_42.7.14-1.debian.tar.xz Files: 086da6a46f697a8f81d33dc933aad648 2426 java optional libpgjava_42.7.14-1.dsc abe9eb01a66a7a2371e5eb154fd5fc93 1224149 java optional libpgjava_42.7.14.orig.tar.gz 86e1b2fac82844b291ec4f280671fe72 11764 java optional libpgjava_42.7.14-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXEj+YVf0kXlZcIfGTFprqxLSp64FAmrItU4ACgkQTFprqxLS p663kQ//QCwMgWr+nYJT1ZbWlwjtGJKzcj8J0tYimgp2gxKZnpk4eIHP+6RLIqcq 293419kM3DUf1gq1pzhxHgwhO+NZQocYiDlUAojaa/4iJDGWKHKxGgMqCyD/DK57 UXKqx6jkYHC6Go6hzeLe6HEU8DgGHkOXUqyoNTZVxh6uJVlT9zTDHr9M0cPc70bP 76kNw9zhDizk9C8Eo7VAloK3E2vcag/mjE0Ceo7c5IU1YWHTB7PZk5uSyqNtb+B9 /A4E1s8aFO4+p9LrrPYKRE1wa4NPSKMuufHvpXCfnpCoFPVCxwiQLtl6GE9wrsvg TU9YS+L+AuXdgTLyCyGebJLq5QOk8jyDHgCjqIwmFZrxqcEAFdljWbPMUkfXQ5Fq KkJPjE9fJtg1MMIrU83jPK9KwRGjN06Xzcqcs8gW+bc2UZop8geuj19cHeZWQUaa 39IoXKo3N/1xE0xQz6I3OerV5ByXTS0VIg+z78LUgdD5YazQCtdU2RcKlxNAT5qD l9UpphixHyKnZ2LBv6j0lnR8fvu4g7ZIUPR8KgGn88rDe1bCHHokAJaMgENg9eNM tmcwUVb0rNFOYQRagJbO8WffINCRYv4Ms4LScGZox/CqmsNjd7zveZIiW8RM4hlk HitTys285CMBtQ8PWHEFX5j3yym85p5Cva1SSIeKnX+guJTaZdo= =bd+B -----END PGP SIGNATURE-----