PT-2018-2663 · Postgresql+3 · Postgresql+3

Sam Fowler

·

Published

2018-08-09

·

Updated

2024-06-15

·

CVE-2018-10925

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PostgreSQL versions prior to 10.5 PostgreSQL versions prior to 9.6.10 PostgreSQL versions prior to 9.5.14 PostgreSQL versions prior to 9.4.19 PostgreSQL versions prior to 9.3.24
Description The issue is related to errors in authorization within the PostgreSQL database management system. It allows a remote attacker to potentially elevate their privileges. Specifically, the vulnerability involves improper authorization checks on certain statements, such as INSERT ... ON CONFLICT DO UPDATE. This could enable an attacker with CREATE TABLE privileges to read arbitrary bytes from server memory. If the attacker also has certain INSERT and limited UPDATE privileges to a particular table, they could exploit this to update other columns in the same table.
Recommendations For versions prior to 10.5, update to version 10.5 or later. For versions prior to 9.6.10, update to version 9.6.10 or later. For versions prior to 9.5.14, update to version 9.5.14 or later. For versions prior to 9.4.19, update to version 9.4.19 or later. For versions prior to 9.3.24, update to version 9.3.24 or later.

Fix

Incorrect Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2131
ALT-PU-2018-2132
ALT-PU-2018-2133
ALT-PU-2018-2136
BDU:2019-01295
CVE-2018-10925
DSA-4269-1
MGASA-2018-0446
OPENSUSE-SU-2018_2599-1
OPENSUSE-SU-2018_3449-1
OPENSUSE-SU-2020:1227-1
OPENSUSE-SU-2020_1227-1
OPENSUSE-SU-2024:11184-1
OPENSUSE-SU-2024:11185-1
RHSA-2018:2511
RHSA-2018:2565
RHSA-2018:2566
RHSA-2018:3816
SUSE-SU-2018:2564-1
SUSE-SU-2018:3377-1
USN-3744-1

Affected Products

Alt Linux
Postgresql
Suse
Ubuntu