CVE-2018-10915
published 2018-08-09CVE-2018-10915: A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an…
PriorityP350high7.5CVSS 3.0
AVNACHPRLUINSUCHIHAH
EPSS
5.15%
91.5th percentile
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could bypass client-side connection security features, obtain access to higher privileged connections or potentially cause other impact through SQL injection, by causing the PQescape() functions to malfunction. Postgresql versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 are affected.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| postgresql | postgresql | >= 0 < 10.5-r0 | 10.5-r0 |
| postgresql | postgresql | >= 0 < 10.5-r0 | 10.5-r0 |
| postgresql | postgresql | >= 0 < 10.5-r0 | 10.5-r0 |
| postgresql | postgresql | >= 0 < 10.5-r0 | 10.5-r0 |
| postgresql | postgresql | >= 0 < 10.5-r0 | 10.5-r0 |
| postgresql | postgresql | >= 0 < 9.6.10-r0 | 9.6.10-r0 |
| postgresql | postgresql | >= 0 < 9.6.10-r0 | 9.6.10-r0 |
| postgresql | postgresql | >= 0 < 10.5-r0 | 10.5-r0 |
| postgresql | postgresql | >= 0 < 10.5-r0 | 10.5-r0 |
| postgresql | postgresql | >= 0 < 10.5-r0 | 10.5-r0 |
| postgresql | postgresql | >= 10.0 < 10.5 | 10.5 |
| postgresql | postgresql | >= 9.3.0 < 9.3.24 | 9.3.24 |
| postgresql | postgresql | >= 9.4.0 < 9.4.19 | 9.4.19 |
| postgresql | postgresql | >= 9.5.0 < 9.5.14 | 9.5.14 |
| postgresql | postgresql | >= 9.6.0 < 9.6.10 | 9.6.10 |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat8.5HIGH
vendor_ubuntu8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q7vw-gjh3-qf97: A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections
ghsa_unreviewed·2022-05-13
CVE-2018-10915 [HIGH] CWE-89 GHSA-q7vw-gjh3-qf97: A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could bypass client-side connection security features, obtain access to higher privileged connections or potentially cause other impact through SQL injection, by causing the PQescape() functions to malfunction. Postgresql versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 are affected.
OSV
postgresql-10, postgresql-9.3, postgresql-9.5 vulnerabilities
osv·2018-08-16·CVSS 7.5
CVE-2018-10915 [HIGH] postgresql-10, postgresql-9.3, postgresql-9.5 vulnerabilities
postgresql-10, postgresql-9.3, postgresql-9.5 vulnerabilities
Andrew Krasichkov discovered that the PostgreSQL client library incorrectly
reset its internal state between connections. A remote attacker could
possibly use this issue to bypass certain client-side connection security
features. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2018-10915)
It was discovered that PostgreSQL incorrectly checked authorization on
certain statements. A remote attacker could possibly use this issue to
read arbitrary server memory or alter certain data. (CVE-2018-10925)
OSV
CVE-2018-10915: A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections
osv·2018-08-09·CVSS 7.5
CVE-2018-10915 [HIGH] CVE-2018-10915: A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could bypass client-side connection security features, obtain access to higher privileged connections or potentially cause other impact through SQL injection, by causing the PQescape() functions to malfunction. Postgresql versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 are affected.
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2018-08-16·CVSS 8.5
CVE-2018-10915 [HIGH] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: Several security issues were fixed in PostgreSQL.
Andrew Krasichkov discovered that the PostgreSQL client library incorrectly
reset its internal state between connections. A remote attacker could
possibly use this issue to bypass certain client-side connection security
features. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2018-10915)
It was discovered that PostgreSQL incorrectly checked authorization on
certain statements. A remote attacker could possibly use this issue to
read arbitrary server memory or alter certain data. (CVE-2018-10925)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart PostgreSQL to
make all the necessary c
Red Hat
postgresql: Certain host connection parameters defeat client-side security defenses
vendor_redhat·2018-08-09·CVSS 8.5
CVE-2018-10915 [HIGH] CWE-89 postgresql: Certain host connection parameters defeat client-side security defenses
postgresql: Certain host connection parameters defeat client-side security defenses
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could bypass client-side connection security features, obtain access to higher privileged connections or potentially cause other impact through SQL injection, by causing the PQescape() functions to malfunction. Postgresql versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 are affected.
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10915 postgresql: Certain host connection parameters defeat client-side security defenses [fedora-all]
bugzilla·2018-08-09·CVSS 8.5
CVE-2018-10915 [HIGH] CVE-2018-10915 postgresql: Certain host connection parameters defeat client-side security defenses [fedora-all]
CVE-2018-10915 postgresql: Certain host connection parameters defeat client-side security defenses [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2018-10915 mingw-postgresql: postgresql: Certain host connection parameters defeat client-side security defenses [epel-7]
bugzilla·2018-08-09·CVSS 8.5
CVE-2018-10915 [HIGH] CVE-2018-10915 mingw-postgresql: postgresql: Certain host connection parameters defeat client-side security defenses [epel-7]
CVE-2018-10915 mingw-postgresql: postgresql: Certain host connection parameters defeat client-side security defenses [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discuss
Bugzilla
CVE-2018-10915 mingw-postgresql: postgresql: Certain host connection parameters defeat client-side security defenses [fedora-all]
bugzilla·2018-08-09·CVSS 8.5
CVE-2018-10915 [HIGH] CVE-2018-10915 mingw-postgresql: postgresql: Certain host connection parameters defeat client-side security defenses [fedora-all]
CVE-2018-10915 mingw-postgresql: postgresql: Certain host connection parameters defeat client-side security defenses [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-10925 postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements
bugzilla·2018-08-06·CVSS 8.5
CVE-2018-10925 [HIGH] CVE-2018-10925 postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements
CVE-2018-10925 postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements
PostgreSQL before versions 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 do not properly authorize certain statements. A attacker able to issue CREATE TABLE can read arbitrary bytes of server memory using INSERT ... ON CONFLICT DO UPDATE. By default, any user can exploit that. If such an attacker also has certain INSERT privileges and has UPDATE privilege on at least one column of a given table, a data integrity attack is possible. The attacker can update other columns, for which the attacker lacks UPDATE privilege.
Discussion:
"ON CONFLICT DO UPDATE" was introduced in PostgreSQL 9.5; versions 9.4 and earlier do not support this feature and thus are not vulnerable to this CVE
Bugzilla
CVE-2018-10915 postgresql: Certain host connection parameters defeat client-side security defenses
bugzilla·2018-07-30·CVSS 8.5
CVE-2018-10915 [HIGH] CVE-2018-10915 postgresql: Certain host connection parameters defeat client-side security defenses
CVE-2018-10915 postgresql: Certain host connection parameters defeat client-side security defenses
A flaw was found in PostgreSQL. The chief PostgreSQL client library, libpq, does not adequately reset its internal state before each connection attempt. When one requests a connection using a "host" or "hostaddr" connection parameter provided by an untrusted party, that party can thwart three security-relevant features of the client. First, they can cause PQconnectionUsedPassword() to erroneously return true. Users of contrib module "dblink" or "postgres_fdw" can leverage that to use server-side login credentials that they should not be able to use. Second, attackers can cause the PQescape*() family of functions to malfunction, permitting SQL injection in "postgres_fdw" and likely in other a
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.htmlhttp://www.securityfocus.com/bid/105054http://www.securitytracker.com/id/1041446https://access.redhat.com/errata/RHSA-2018:2511https://access.redhat.com/errata/RHSA-2018:2557https://access.redhat.com/errata/RHSA-2018:2565https://access.redhat.com/errata/RHSA-2018:2566https://access.redhat.com/errata/RHSA-2018:2643https://access.redhat.com/errata/RHSA-2018:2721https://access.redhat.com/errata/RHSA-2018:2729https://access.redhat.com/errata/RHSA-2018:3816https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10915https://lists.debian.org/debian-lts-announce/2018/08/msg00012.htmlhttps://security.gentoo.org/glsa/201810-08https://usn.ubuntu.com/3744-1/https://www.debian.org/security/2018/dsa-4269https://www.postgresql.org/about/news/1878/http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.htmlhttp://www.securityfocus.com/bid/105054http://www.securitytracker.com/id/1041446https://access.redhat.com/errata/RHSA-2018:2511https://access.redhat.com/errata/RHSA-2018:2557https://access.redhat.com/errata/RHSA-2018:2565https://access.redhat.com/errata/RHSA-2018:2566https://access.redhat.com/errata/RHSA-2018:2643https://access.redhat.com/errata/RHSA-2018:2721https://access.redhat.com/errata/RHSA-2018:2729https://access.redhat.com/errata/RHSA-2018:3816https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10915https://lists.debian.org/debian-lts-announce/2018/08/msg00012.htmlhttps://security.gentoo.org/glsa/201810-08https://usn.ubuntu.com/3744-1/https://www.debian.org/security/2018/dsa-4269https://www.postgresql.org/about/news/1878/
2018-08-09
Published