Логотип exploitDog
product: "postgresql"
Консоль
Логотип exploitDog

exploitDog

product: "postgresql"
PostgreSQL

PostgreSQLсвободная объектно-реляционная система управления базами данных.

Релизный цикл, информация об уязвимостях

Продукт: PostgreSQL
Вендор: PostgreSQL

График релизов

141516171820212022202320242025202620272028202920302031

Недавние уязвимости PostgreSQL

Количество 1 017

ubuntu логотип

CVE-2019-9193

почти 7 лет назад

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.

CVSS3: 7.2
EPSS: Критический
redhat логотип

CVE-2019-9193

около 7 лет назад

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2018:3770-2

больше 7 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:4031-1

больше 7 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:4007-1

больше 7 лет назад

Security update for postgresql94

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:3942-1

больше 7 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:3909-1

больше 7 лет назад

Security update for postgresql94

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:3893-1

больше 7 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:3770-1

больше 7 лет назад

Security update for postgresql10

EPSS: Низкий
nvd логотип

CVE-2018-16850

больше 7 лет назад

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2019-9193

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.

CVSS3: 7.2
93%
Критический
почти 7 лет назад
redhat логотип
CVE-2019-9193

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.

93%
Критический
около 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:3770-2

Security update for postgresql10

1%
Низкий
больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:4031-1

Security update for postgresql10

1%
Низкий
больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:4007-1

Security update for postgresql94

2%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:3942-1

Security update for postgresql10

1%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:3909-1

Security update for postgresql94

2%
Низкий
больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:3893-1

Security update for postgresql10

1%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:3770-1

Security update for postgresql10

1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-16850

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

CVSS3: 9.8
1%
Низкий
больше 7 лет назад

Уязвимостей на страницу


Поделиться