Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1058

Опубликовано: 01 мар. 2018
Источник: redhat
CVSS3: 8.8
EPSS Высокий

Описание

A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.

A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database.

Отчет

This issue affects the versions of Postgresql as shipped with Red Hat Satellite 5. Red Hat Product Security has rated this issue as having security impact of Low. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Меры по смягчению последствий

Upstream suggests the following mitigation can be used to protect against this security flaw: https://wiki.postgresql.org/wiki/A_Guide_to_CVE-2018-1058:_Protect_Your_Search_Path

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5postgresql94Will not fix
Red Hat Enterprise Linux 5postgresqlWill not fix
Red Hat Enterprise Linux 5postgresql84Will not fix
Red Hat Enterprise Linux 6postgresqlWill not fix
Red Hat Enterprise Linux 7postgresqlWill not fix
Red Hat Enterprise Linux 8postgresqlNot affected
Red Hat JBoss Fuse Service Works 6postgresqlNot affected
Red Hat JBoss Operations Network 3postgresqlNot affected
Red Hat Mobile Application Platform 4postgresqlNot affected
Red Hat Satellite 5postgresql95-postgresqlWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1547044postgresql: Uncontrolled search path element in pg_dump and other client applications

EPSS

Процентиль: 99%
0.83121
Высокий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.

CVSS3: 8.8
nvd
больше 7 лет назад

A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.

CVSS3: 8.8
debian
больше 7 лет назад

A flaw was found in the way Postgresql allowed a user to modify the be ...

suse-cvrf
около 7 лет назад

Security update for postgresql94

suse-cvrf
около 7 лет назад

Security update for postgresql96

EPSS

Процентиль: 99%
0.83121
Высокий

8.8 High

CVSS3