PT-2016-6421 · Postgresql+4 · Postgresql+4

Michael Paquier

+2

·

Publicado

2016-08-11

·

Atualizado

2024-06-15

·

CVE-2016-5424

CVSS v3.1

7.1

Alta

VetorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PostgreSQL versions prior to 9.1.23 PostgreSQL versions 9.2.x prior to 9.2.18 PostgreSQL versions 9.3.x prior to 9.3.14 PostgreSQL versions 9.4.x prior to 9.4.9 PostgreSQL versions 9.5.x prior to 9.5.4
Description The issue allows remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a mishandled database or role name that contains specific characters, including a double quote, backslash, carriage return, or newline character, during an administrative operation.
Recommendations For versions prior to 9.1.23, update to version 9.1.23 or later. For versions 9.2.x prior to 9.2.18, update to version 9.2.18 or later. For versions 9.3.x prior to 9.3.14, update to version 9.3.14 or later. For versions 9.4.x prior to 9.4.9, update to version 9.4.9 or later. For versions 9.5.x prior to 9.5.4, update to version 9.5.4 or later.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2016_2606
CVE-2016-5424
DLA-592-1
DSA-3646-1
MGASA-2016-0289
OPENSUSE-SU-2016_2425-1
OPENSUSE-SU-2016_2464-1
OPENSUSE-SU-2017_1021-1
OPENSUSE-SU-2024:10030-1
OPENSUSE-SU-2024:10256-1
OPENSUSE-SU-2024:10273-1
RHSA-2016:1781
RHSA-2016:1820
RHSA-2016:1821
RHSA-2016:2606
RHSA-2016_2606
RHSA-2017:2425
SUSE-SU-2016:2414-1
SUSE-SU-2016:2415-1
SUSE-SU-2016:2418-1
USN-3066-1

Produtos afetados

Centos
Postgresql
Red Hat
Suse
Ubuntu