PT-2013-6351 · Postgresql+1 · Postgresql+5

Kyotaro Horiguchi

+1

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2013-1899

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PostgreSQL versions 9.2.x before 9.2.4 PostgreSQL versions 9.1.x before 9.1.9 PostgreSQL versions 9.0.x before 9.0.13 libpq5-x86 (affected versions not specified) libecpg6 (affected versions not specified) libpq5 (affected versions not specified) libpq5-32bit (affected versions not specified)
Description The issue allows remote attackers to cause a denial of service, and allows remote authenticated users to modify configuration settings and execute arbitrary code. A connection request containing a database name that begins with a "-" (hyphen) may be crafted to damage or destroy files within a server's data directory. The exploitation of the vulnerabilities may lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely by an attacker who has passed the authentication procedure.
Recommendations For PostgreSQL versions 9.2.x before 9.2.4, update to version 9.2.4 or later. For PostgreSQL versions 9.1.x before 9.1.9, update to version 9.1.9 or later. For PostgreSQL versions 9.0.x before 9.0.13, update to version 9.0.13 or later. For libpq5-x86, libecpg6, libpq5, and libpq5-32bit, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the vulnerable components to minimize the risk of exploitation. Avoid using database names that begin with a "-" (hyphen) in connection requests until the issue is resolved.

Exploit

DoS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04511
BDU:2015-04512
BDU:2015-04513
BDU:2015-04514
CVE-2013-1899
DSA-2658-1
OPENSUSE-SU-2013_0627-1
OPENSUSE-SU-2013_0628-1
OPENSUSE-SU-2013_0635-1
OPENSUSE-SU-2024:10030-1
OPENSUSE-SU-2024:10256-1
OPENSUSE-SU-2024:10273-1
SUSE-SU-2013_0633-1
SUSE-SU-2013_0633-2

Affected Products

Postgresql
Suse
Libecpg6
Libpq5
Libpq5-32Bit
Libpq5-X86