Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-16082

Опубликовано: 07 июн. 2018
Источник: debian

Описание

A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-postgresfixed7.7.1-1package

Примечания

  • https://nodesecurity.io/advisories/521

  • nodejs not covered by security support

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.

CVSS3: 9.8
nvd
больше 7 лет назад

A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.

CVSS3: 9.8
github
больше 7 лет назад

Remote Code Execution in pg