Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PostgreSQL

PostgreSQLсвободная объектно-реляционная система управления базами данных.

Релизный цикл, информация об уязвимостях

Продукт: PostgreSQL
Вендор: PostgreSQL

График релизов

141516171820212022202320242025202620272028202920302031

Релизные элементы

KBВерсияБилдДата доступности
17.1017.10
17.917.9
17.817.8
17.717.7
17.617.6
17.517.5
17.417.4
17.317.3
17.217.2
17.117.1

Показывать по

Недавние уязвимости PostgreSQL

Количество 1 129

redhat логотип

CVE-2019-9193

больше 7 лет назад

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2018:3770-2

больше 7 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:4031-1

больше 7 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:4007-1

больше 7 лет назад

Security update for postgresql94

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:3942-1

больше 7 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:3909-1

больше 7 лет назад

Security update for postgresql94

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:3893-1

больше 7 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2018:3770-1

больше 7 лет назад

Security update for postgresql10

EPSS: Низкий
nvd логотип

CVE-2018-16850

больше 7 лет назад

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2018-16850

больше 7 лет назад

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL inject ...

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2019-9193

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.

92%
Критический
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:3770-2

Security update for postgresql10

5%
Низкий
больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:4031-1

Security update for postgresql10

5%
Низкий
больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:4007-1

Security update for postgresql94

5%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:3942-1

Security update for postgresql10

5%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:3909-1

Security update for postgresql94

5%
Низкий
больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:3893-1

Security update for postgresql10

5%
Низкий
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:3770-1

Security update for postgresql10

5%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-16850

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

CVSS3: 9.8
5%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-16850

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL inject ...

CVSS3: 9.8
5%
Низкий
больше 7 лет назад

Уязвимостей на страницу


Поделиться