Описание
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.
Релиз | Статус | Примечание |
---|---|---|
artful | DNE | |
bionic | released | 10.3-1 |
cosmic | released | 10.3-1 |
devel | DNE | |
disco | DNE | |
esm-infra-legacy/trusty | DNE | |
esm-infra/bionic | not-affected | 10.3-1 |
precise/esm | DNE | |
trusty | DNE | |
trusty/esm | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
artful | DNE | |
bionic | DNE | |
cosmic | DNE | |
devel | DNE | |
disco | DNE | |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needs-triage] |
precise/esm | ignored | |
trusty | ignored | end of standard support |
trusty/esm | DNE | trusty was needs-triage |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
artful | DNE | |
bionic | DNE | |
cosmic | DNE | |
devel | DNE | |
disco | DNE | |
esm-infra-legacy/trusty | not-affected | 9.3.22-0ubuntu0.14.04 |
precise/esm | DNE | |
trusty | released | 9.3.22-0ubuntu0.14.04 |
trusty/esm | not-affected | 9.3.22-0ubuntu0.14.04 |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
artful | DNE | |
bionic | DNE | |
cosmic | DNE | |
devel | DNE | |
disco | DNE | |
esm-infra-legacy/trusty | DNE | |
esm-infra/xenial | not-affected | 9.5.12-0ubuntu0.16.04 |
precise/esm | DNE | |
trusty | DNE | |
trusty/esm | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
artful | released | 9.6.8-0ubuntu0.17.10 |
bionic | DNE | |
cosmic | DNE | |
devel | DNE | |
disco | DNE | |
esm-infra-legacy/trusty | DNE | |
precise/esm | DNE | |
trusty | DNE | |
trusty/esm | DNE | |
upstream | needs-triage |
Показывать по
EPSS
6.5 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.
A flaw was found in the way Postgresql allowed a user to modify the be ...
EPSS
6.5 Medium
CVSS2
8.8 High
CVSS3