Логотип exploitDog
product: "postgresql"
Консоль
Логотип exploitDog

exploitDog

product: "postgresql"
PostgreSQL

PostgreSQLсвободная объектно-реляционная система управления базами данных.

Релизный цикл, информация об уязвимостях

Продукт: PostgreSQL
Вендор: PostgreSQL

График релизов

131415161720202021202220232024202520262027202820292030

Недавние уязвимости PostgreSQL

Количество 970

nvd логотип

CVE-2019-9193

больше 6 лет назад

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.

CVSS3: 7.2
EPSS: Критический
debian логотип

CVE-2019-9193

больше 6 лет назад

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function al ...

CVSS3: 7.2
EPSS: Критический
ubuntu логотип

CVE-2019-9193

больше 6 лет назад

** DISPUTED ** In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.

CVSS3: 7.2
EPSS: Критический
redhat логотип

CVE-2019-9193

больше 6 лет назад

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2018:3770-2

больше 6 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:4031-1

больше 6 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:4007-1

больше 6 лет назад

Security update for postgresql94

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:3942-1

больше 6 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:3909-1

больше 6 лет назад

Security update for postgresql94

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:3893-1

больше 6 лет назад

Security update for postgresql10

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2019-9193

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.

CVSS3: 7.2
94%
Критический
больше 6 лет назад
debian логотип
CVE-2019-9193

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function al ...

CVSS3: 7.2
94%
Критический
больше 6 лет назад
ubuntu логотип
CVE-2019-9193

** DISPUTED ** In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.

CVSS3: 7.2
94%
Критический
больше 6 лет назад
redhat логотип
CVE-2019-9193

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.

94%
Критический
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2018:3770-2

Security update for postgresql10

1%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2018:4031-1

Security update for postgresql10

1%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2018:4007-1

Security update for postgresql94

2%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2018:3942-1

Security update for postgresql10

1%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2018:3909-1

Security update for postgresql94

2%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2018:3893-1

Security update for postgresql10

1%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться