CVE-2018-10925
published 2018-08-09CVE-2018-10925: It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements…
PriorityP349high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
2.24%
80.9th percentile
It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "CREATE TABLE" privileges could exploit this to read arbitrary bytes server memory. If the attacker also had certain "INSERT" and limited "UPDATE" privileges to a particular table, they could exploit this to update other columns in the same table.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| postgresql | postgresql | >= 0 < 10.5-r0 | 10.5-r0 |
| postgresql | postgresql | >= 0 < 10.5-r0 | 10.5-r0 |
| postgresql | postgresql | >= 0 < 10.5-r0 | 10.5-r0 |
| postgresql | postgresql | >= 0 < 10.5-r0 | 10.5-r0 |
| postgresql | postgresql | >= 0 < 10.5-r0 | 10.5-r0 |
| postgresql | postgresql | >= 0 < 9.6.10-r0 | 9.6.10-r0 |
| postgresql | postgresql | >= 0 < 9.6.10-r0 | 9.6.10-r0 |
| postgresql | postgresql | >= 0 < 10.5-r0 | 10.5-r0 |
| postgresql | postgresql | >= 0 < 10.5-r0 | 10.5-r0 |
| postgresql | postgresql | >= 0 < 10.5-r0 | 10.5-r0 |
| postgresql | postgresql | >= 10.0 < 10.5 | 10.5 |
| postgresql | postgresql | >= 9.5.0 < 9.5.14 | 9.5.14 |
| postgresql | postgresql | >= 9.6.0 < 9.6.10 | 9.6.10 |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv3.07.1HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
osv8.1HIGH
vendor_ubuntu8.5HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mr45-mwhc-fw72: It was discovered that PostgreSQL versions before 10
ghsa_unreviewed·2022-05-13
CVE-2018-10925 [HIGH] CWE-863 GHSA-mr45-mwhc-fw72: It was discovered that PostgreSQL versions before 10
It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "CREATE TABLE" privileges could exploit this to read arbitrary bytes server memory. If the attacker also had certain "INSERT" and limited "UPDATE" privileges to a particular table, they could exploit this to update other columns in the same table.
OSV
postgresql-10, postgresql-9.3, postgresql-9.5 vulnerabilities
osv·2018-08-16·CVSS 7.5
CVE-2018-10915 [HIGH] postgresql-10, postgresql-9.3, postgresql-9.5 vulnerabilities
postgresql-10, postgresql-9.3, postgresql-9.5 vulnerabilities
Andrew Krasichkov discovered that the PostgreSQL client library incorrectly
reset its internal state between connections. A remote attacker could
possibly use this issue to bypass certain client-side connection security
features. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2018-10915)
It was discovered that PostgreSQL incorrectly checked authorization on
certain statements. A remote attacker could possibly use this issue to
read arbitrary server memory or alter certain data. (CVE-2018-10925)
OSV
CVE-2018-10925: It was discovered that PostgreSQL versions before 10
osv·2018-08-09·CVSS 8.1
CVE-2018-10925 [HIGH] CVE-2018-10925: It was discovered that PostgreSQL versions before 10
It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "CREATE TABLE" privileges could exploit this to read arbitrary bytes server memory. If the attacker also had certain "INSERT" and limited "UPDATE" privileges to a particular table, they could exploit this to update other columns in the same table.
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2018-08-16·CVSS 8.5
CVE-2018-10915 [HIGH] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: Several security issues were fixed in PostgreSQL.
Andrew Krasichkov discovered that the PostgreSQL client library incorrectly
reset its internal state between connections. A remote attacker could
possibly use this issue to bypass certain client-side connection security
features. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2018-10915)
It was discovered that PostgreSQL incorrectly checked authorization on
certain statements. A remote attacker could possibly use this issue to
read arbitrary server memory or alter certain data. (CVE-2018-10925)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart PostgreSQL to
make all the necessary c
Red Hat
postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements
vendor_redhat·2018-08-09·CVSS 8.1
CVE-2018-10925 [HIGH] CWE-863 postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements
postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements
It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "CREATE TABLE" privileges could exploit this to read arbitrary bytes server memory. If the attacker also had certain "INSERT" and limited "UPDATE" privileges to a particular table, they could exploit this to update other columns in the same table.
It was discovered that PostgreSQL failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "CREATE TABLE" privileges could exploit this to read arbitrary byt
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10925 mingw-postgresql: postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements [fedora-all]
bugzilla·2018-08-09·CVSS 8.1
CVE-2018-10925 [HIGH] CVE-2018-10925 mingw-postgresql: postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements [fedora-all]
CVE-2018-10925 mingw-postgresql: postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpk
Bugzilla
CVE-2018-10925 mingw-postgresql: postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements [epel-7]
bugzilla·2018-08-09·CVSS 8.1
CVE-2018-10925 [HIGH] CVE-2018-10925 mingw-postgresql: postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements [epel-7]
CVE-2018-10925 mingw-postgresql: postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2018-10925 postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements [fedora-all]
bugzilla·2018-08-09·CVSS 8.1
CVE-2018-10925 [HIGH] CVE-2018-10925 postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements [fedora-all]
CVE-2018-10925 postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-10925 postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements
bugzilla·2018-08-06·CVSS 8.5
CVE-2018-10925 [HIGH] CVE-2018-10925 postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements
CVE-2018-10925 postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements
PostgreSQL before versions 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 do not properly authorize certain statements. A attacker able to issue CREATE TABLE can read arbitrary bytes of server memory using INSERT ... ON CONFLICT DO UPDATE. By default, any user can exploit that. If such an attacker also has certain INSERT privileges and has UPDATE privilege on at least one column of a given table, a data integrity attack is possible. The attacker can update other columns, for which the attacker lacks UPDATE privilege.
Discussion:
"ON CONFLICT DO UPDATE" was introduced in PostgreSQL 9.5; versions 9.4 and earlier do not support this feature and thus are not vulnerable to this CVE
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.htmlhttp://www.securityfocus.com/bid/105052http://www.securitytracker.com/id/1041446https://access.redhat.com/errata/RHSA-2018:2511https://access.redhat.com/errata/RHSA-2018:2565https://access.redhat.com/errata/RHSA-2018:2566https://access.redhat.com/errata/RHSA-2018:3816https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10925https://security.gentoo.org/glsa/201810-08https://usn.ubuntu.com/3744-1/https://www.debian.org/security/2018/dsa-4269https://www.postgresql.org/about/news/1878/http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.htmlhttp://www.securityfocus.com/bid/105052http://www.securitytracker.com/id/1041446https://access.redhat.com/errata/RHSA-2018:2511https://access.redhat.com/errata/RHSA-2018:2565https://access.redhat.com/errata/RHSA-2018:2566https://access.redhat.com/errata/RHSA-2018:3816https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10925https://security.gentoo.org/glsa/201810-08https://usn.ubuntu.com/3744-1/https://www.debian.org/security/2018/dsa-4269https://www.postgresql.org/about/news/1878/
2018-08-09
Published