Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1058

Опубликовано: 02 мар. 2018
Источник: debian

Описание

A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
postgresql-10fixed10.3-1package
postgresql-9.6removedpackage
postgresql-9.6fixed9.6.8-0+deb9u1stretchpackage
postgresql-9.4removedpackage
postgresql-9.4fixed9.4.17-0+deb8u1jessiepackage
postgresql-9.1removedpackage
postgresql-9.1not-affectedjessiepackage
postgresql-9.1no-dsawheezypackage

Примечания

  • https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=3d2aed664ee8271fd6c721ed0aa10168cda112ea

  • https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=582edc369cdbd348d68441fc50fa26a84afd0c1a

  • https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=5770172cb0c9df9e6ce27c507b449557e5b45124

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.

CVSS3: 8.8
redhat
больше 7 лет назад

A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.

CVSS3: 8.8
nvd
больше 7 лет назад

A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.

suse-cvrf
около 7 лет назад

Security update for postgresql94

suse-cvrf
около 7 лет назад

Security update for postgresql96