Lucene search

K
kasperskyKaspersky LabKLA11196
HistoryFeb 08, 2018 - 12:00 a.m.

KLA11196 Multiple vulnerabilities in PostgreSQL

2018-02-0800:00:00
Kaspersky Lab
threats.kaspersky.com
41

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

26.4%

Multiple serious vulnerabilities have been found in PostgreSQL. Malicious users can exploit these vulnerabilities to bypass security restrictions and obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. A memory disclosure vulnerability in table partitioning can be exploited remotely to bypass security restrictions via purpose-crafted insert to a partitioned table;
  2. An unspecified vulnerability related to creating files in current working directory can be exploited to obtain sensitive information via reading or modifying file with database passwords.

Original advisories

Security Information

Related products

PostgreSQL

CVE list

CVE-2018-1053 warning

CVE-2018-1052 warning

Solution

Update to the latest version

Download PostgreSQL

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

Affected Products

  • PostgreSQL 9.3 earlier than 9.3.21PostgreSQL 9.4 earlier than 9.4.16PostgreSQL 9.5 earlier than 9.5.11PostgreSQL 9.6 earlier than 9.6.7PostgreSQL 10 earlier than 10.2

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

26.4%