Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16850

Опубликовано: 08 нояб. 2018
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

A SQL Injection flaw has been discovered in PostgreSQL server in the way triggers that enable transition relations are dumped. The transition relation name is not correctly quoted and it may allow an attacker with CREATE privilege on some non-temporary schema or TRIGGER privilege on some table to create a malicious trigger that, when dumped and restored, would result in additional SQL statements being executed.

Отчет

This issue did not affect the versions of postgresql as shipped with Red Hat Enterprise Linux 5, 6, and 7 as they did not include support for triggers with referecing syntax, which was included in a later version of the program. It also doesn't affect the versions of postgresql shipped with CloudForms 4.2, 4.5 and 4.6, and Satellite 5, for the same reason as above. This issue did not affect the versions of postgresql shipped within Tower, as there is no code path for Tower users to call the CREATE statement.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5postgresql96Not affected
Red Hat Ansible Tower 3postgresql96-libsNot affected
Red Hat Enterprise Linux 5postgresqlNot affected
Red Hat Enterprise Linux 6postgresqlNot affected
Red Hat Enterprise Linux 7postgresqlNot affected
Red Hat Enterprise Linux 8libpqNot affected
Red Hat Enterprise Linux 8postgresqlNot affected
Red Hat Satellite 5rh-postgresql95-postgresqlNot affected
Red Hat Software Collectionsrh-postgresql95-postgresqlNot affected
Red Hat Software Collectionsrh-postgresql96-postgresqlNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=1645937postgresql: SQL injection in pg_upgrade and pg_dump, via CREATE TRIGGER ... REFERENCING

EPSS

Процентиль: 79%
0.01312
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

CVSS3: 9.8
nvd
больше 6 лет назад

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

CVSS3: 9.8
debian
больше 6 лет назад

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL inject ...

suse-cvrf
больше 6 лет назад

Security update for postgresql10

suse-cvrf
больше 6 лет назад

Security update for postgresql10

EPSS

Процентиль: 79%
0.01312
Низкий

8 High

CVSS3