PT-2025-6477 · Postgresql+12 · Postgresql+12
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PostgreSQL versions prior to 17.3
PostgreSQL versions prior to 16.7
PostgreSQL versions prior to 15.11
PostgreSQL versions prior to 14.16
PostgreSQL versions prior to 13.19
Description
The issue is related to improper neutralization of quoting syntax in PostgreSQL libpq functions, specifically
PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn(). This allows a database input provider to achieve SQL injection in certain usage patterns, particularly when the application uses the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client encoding is BIG5 and server encoding is one of EUC TW or MULE INTERNAL. The vulnerability has been exploited in real-world attacks, including the US Treasury hack, and is considered high-severity.Recommendations
For versions prior to 17.3, update to version 17.3 or later.
For versions prior to 16.7, update to version 16.7 or later.
For versions prior to 15.11, update to version 15.11 or later.
For versions prior to 14.16, update to version 14.16 or later.
For versions prior to 13.19, update to version 13.19 or later.
As a temporary workaround, consider restricting access to the
psql tool and limiting the use of the vulnerable libpq functions until a patch is applied.Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Postgresql
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Zvirt Node