Описание
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.
A flaw was found in PostgreSQL. An object creator can exploit a type confusion vulnerability in the pg_restore_attribute_stats() function. This flaw occurs due to the conflation of range and multirange values, allowing the attacker to execute arbitrary code as the operating system user running the database. This could lead to a complete compromise of the database system.
Отчет
A type confusion flaw in PostgreSQL’s pg_restore_attribute_stats() function allows an authenticated user with object-creation privileges to achieve arbitrary code execution under the database server process (postgres) via crafted range and multirange values. Note: Red Hat Enterprise Linux 9.6 and earlier releases do not ship the vulnerable PostgreSQL major version (18.x) and are therefore not affected.
Меры по смягчению последствий
To mitigate this issue, restrict the ability to create database objects and perform database restorations to only highly trusted administrative users. This operational control limits the attack surface by ensuring that only authorized personnel can introduce potentially malicious objects into the database environment. Carefully manage user privileges to enforce this restriction.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | postgresql16 | Not affected | ||
| Red Hat Enterprise Linux 10 | postgresql18 | Affected | ||
| Red Hat Enterprise Linux 6 | postgresql | Not affected | ||
| Red Hat Enterprise Linux 7 | postgresql | Not affected | ||
| Red Hat Enterprise Linux 8 | postgresql:12/postgresql | Not affected | ||
| Red Hat Enterprise Linux 8 | postgresql:15/postgresql | Not affected | ||
| Red Hat Enterprise Linux 8 | postgresql:16/postgresql | Not affected | ||
| Red Hat Enterprise Linux 9 | postgresql | Not affected | ||
| Red Hat Enterprise Linux 9 | postgresql:15/postgresql | Not affected | ||
| Red Hat Enterprise Linux 9 | postgresql:16/postgresql | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an ob ...
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.
EPSS
8.8 High
CVSS3