PT-2018-2621 · Postgresql+5 · Postgresql+5

Andrew Krasichkov

·

Published

2018-07-30

·

Updated

2024-06-15

·

CVE-2018-10915

CVSS v3.1

8.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Postgresql versions prior to 10.5 Postgresql versions prior to 9.6.10 Postgresql versions prior to 9.5.14 Postgresql versions prior to 9.4.19 Postgresql versions prior to 9.3.24
Description A vulnerability was found in libpq, the default PostgreSQL client library, where it failed to properly reset its internal state between connections. If an affected version of libpq was used with host or hostaddr connection parameters from untrusted input, attackers could bypass client-side connection security features, obtain access to higher privileged connections, or potentially cause other impact through SQL injection by causing the PQescape() function to malfunction.
Recommendations For versions prior to 10.5, update to version 10.5 or later. For versions prior to 9.6.10, update to version 9.6.10 or later. For versions prior to 9.5.14, update to version 9.5.14 or later. For versions prior to 9.4.19, update to version 9.4.19 or later. For versions prior to 9.3.24, update to version 9.3.24 or later. As a temporary workaround, consider restricting the use of the host and hostaddr connection parameters to trusted input only, until a patch is available.

Fix

Improper Initialization

RCE

Information Disclosure

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2131
ALT-PU-2018-2132
ALT-PU-2018-2133
ALT-PU-2018-2134
ALT-PU-2018-2135
ALT-PU-2018-2136
BDU:2019-01231
CESA-2018_2557
CVE-2018-10915
DLA-1464-1
DSA-4269-1
MGASA-2018-0446
OPENSUSE-SU-2018_2599-1
OPENSUSE-SU-2018_3449-1
OPENSUSE-SU-2018_4007-1
OPENSUSE-SU-2020:1227-1
OPENSUSE-SU-2020_1227-1
OPENSUSE-SU-2024:11184-1
RHSA-2018:2511
RHSA-2018:2557
RHSA-2018:2565
RHSA-2018:2566
RHSA-2018:2643
RHSA-2018:3816
RHSA-2018_2557
SUSE-SU-2018:2564-1
SUSE-SU-2018:3287-1
SUSE-SU-2018:3377-1
SUSE-SU-2018:3909-1
SUSE-SU-2018_2564-1
SUSE-SU-2018_3287-1
SUSE-SU-2018_3377-1
SUSE-SU-2018_3909-1
USN-3744-1

Affected Products

Alt Linux
Centos
Postgresql
Red Hat
Suse
Ubuntu