Vulnerability CVE-2018-16850


Published: 2018-11-13

Description:
postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Redhat -> Enterprise linux 
Postgresql -> Postgresql 
Canonical -> Ubuntu linux 

 References:
http://www.securityfocus.com/bid/105923
http://www.securitytracker.com/id/1042144
https://access.redhat.com/errata/RHSA-2018:3757
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16850
https://security.gentoo.org/glsa/201811-24
https://usn.ubuntu.com/3818-1/
https://www.postgresql.org/about/news/1905/

Copyright 2024, cxsecurity.com

 

Back to Top