Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.144710
Kategorie:Databases
Titel:PostgreSQL < 9.5.23, 9.6.x < 9.6.19, 10.x < 10.14, 11.x < 11.9, 12.x < 12.4 Search Path Vulnerability - Windows
Zusammenfassung:PostgreSQL is prone to an uncontrolled search path element vulnerability in; CREATE EXTENSION.
Beschreibung:Summary:
PostgreSQL is prone to an uncontrolled search path element vulnerability in
CREATE EXTENSION.

Vulnerability Impact:
When a superuser runs certain CREATE EXTENSION statements, users may be able to
execute arbitrary SQL functions under the identity of that superuser. The attacker must have permission to
create objects in the new extension's schema or a schema of a prerequisite extension. Not all extensions are
vulnerable.

Affected Software/OS:
PostgreSQL versions prior to 9.5.23, 9.6.x prior to 9.6.19, 10.x prior to
10.14, 11.x prior to 11.9 and 12.x prior to 12.4.

Solution:
Update to version 9.5.23, 9.6.19, 10.14, 11.9, 12.4 or later.

CVSS Score:
4.4

CVSS Vector:
AV:L/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2020-14350
Debian Security Information: [debian-lts-announce] 20200817 [SECURITY] [DLA 2331-1] posgresql-9.6 security update (Google Search)
https://lists.debian.org/debian-lts-announce/2020/08/msg00028.html
https://security.gentoo.org/glsa/202008-13
https://bugzilla.redhat.com/show_bug.cgi?id=1865746
SuSE Security Announcement: openSUSE-SU-2020:1227 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.html
SuSE Security Announcement: openSUSE-SU-2020:1228 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00044.html
SuSE Security Announcement: openSUSE-SU-2020:1243 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00050.html
SuSE Security Announcement: openSUSE-SU-2020:1244 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00049.html
SuSE Security Announcement: openSUSE-SU-2020:1312 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00003.html
SuSE Security Announcement: openSUSE-SU-2020:1326 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00008.html
https://usn.ubuntu.com/4472-1/
CopyrightCopyright (C) 2020 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.