Описание
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
A flaw was found in PostgreSQL fuzzystrmatch. A low-privileged database user can exploit an integer wraparound vulnerability by providing extreme inputs to the levenshtein() or levenshtein_less_equal() SQL functions. This allows the user to execute arbitrary code as the operating system user running the database, potentially leading to full system compromise.
Отчет
This vulnerability in the PostgreSQL fuzzystrmatch extension is rated as Important. A low-privileged database user could achieve arbitrary code execution as the operating system user running the database. This risk is present only when the fuzzystrmatch extension is explicitly installed and utilized, as it is not enabled by default in Red Hat deployments. The flaw stems from an integer wraparound when processing extreme inputs to specific SQL functions.
Меры по смягчению последствий
To mitigate this issue, consider disabling the fuzzystrmatch extension within PostgreSQL if its functionality is not essential. Alternatively, the postgresql-fuzzystrmatch package can be removed. Disabling or removing the extension may affect applications that rely on the levenshtein() or levenshtein_less_equal() functions. A database service restart may be required for these changes to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | postgresql16 | Affected | ||
| Red Hat Enterprise Linux 10 | postgresql18 | Affected | ||
| Red Hat Enterprise Linux 6 | postgresql | Out of support scope | ||
| Red Hat Enterprise Linux 7 | postgresql | Affected | ||
| Red Hat Enterprise Linux 8 | postgresql:12/postgresql | Affected | ||
| Red Hat Enterprise Linux 8 | postgresql:15/postgresql | Affected | ||
| Red Hat Enterprise Linux 8 | postgresql:16/postgresql | Affected | ||
| Red Hat Enterprise Linux 9 | postgresql | Affected | ||
| Red Hat Enterprise Linux 9 | postgresql:15/postgresql | Affected | ||
| Red Hat Enterprise Linux 9 | postgresql:16/postgresql | Affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct ...
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
7.5 High
CVSS3