PostgreSQL — свободная объектно-реляционная система управления базами данных.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 017
CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.
CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.
SUSE-SU-2018:3770-2
Security update for postgresql10
openSUSE-SU-2018:4031-1
Security update for postgresql10
openSUSE-SU-2018:4007-1
Security update for postgresql94
SUSE-SU-2018:3942-1
Security update for postgresql10
SUSE-SU-2018:3909-1
Security update for postgresql94
openSUSE-SU-2018:3893-1
Security update for postgresql10
SUSE-SU-2018:3770-1
Security update for postgresql10
CVE-2018-16850
postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2019-9193 In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’. | CVSS3: 7.2 | 93% Критический | почти 7 лет назад | |
CVE-2019-9193 In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’. | 93% Критический | около 7 лет назад | ||
SUSE-SU-2018:3770-2 Security update for postgresql10 | 1% Низкий | больше 7 лет назад | ||
openSUSE-SU-2018:4031-1 Security update for postgresql10 | 1% Низкий | больше 7 лет назад | ||
openSUSE-SU-2018:4007-1 Security update for postgresql94 | 2% Низкий | больше 7 лет назад | ||
SUSE-SU-2018:3942-1 Security update for postgresql10 | 1% Низкий | больше 7 лет назад | ||
SUSE-SU-2018:3909-1 Security update for postgresql94 | 2% Низкий | больше 7 лет назад | ||
openSUSE-SU-2018:3893-1 Security update for postgresql10 | 1% Низкий | больше 7 лет назад | ||
SUSE-SU-2018:3770-1 Security update for postgresql10 | 1% Низкий | больше 7 лет назад | ||
CVE-2018-16850 postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges. | CVSS3: 9.8 | 1% Низкий | больше 7 лет назад |
Уязвимостей на страницу