Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-16850

Опубликовано: 13 нояб. 2018
Источник: debian
EPSS Низкий

Описание

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
postgresql-11fixed11.1-1package
postgresql-10removedpackage
postgresql-9.6not-affectedpackage
postgresql-9.4not-affectedpackage
postgresql-9.1not-affectedpackage

Примечания

  • https://www.postgresql.org/about/news/1905/

  • Fixed in 11.1, 10.6

EPSS

Процентиль: 79%
0.01312
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

CVSS3: 8
redhat
больше 6 лет назад

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

CVSS3: 9.8
nvd
больше 6 лет назад

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

suse-cvrf
больше 6 лет назад

Security update for postgresql10

suse-cvrf
больше 6 лет назад

Security update for postgresql10

EPSS

Процентиль: 79%
0.01312
Низкий