Beschreibung
Multiple serious vulnerabilities were found in PostgreSQL. Malicious users can exploit these vulnerabilities to bypass security restrictions and obtain sensitive information.
Below is a complete list of vulnerabilities:
- An unspecified vulnerability in libpq can be exploited remotely to bypass security restrictions;
- An unspecified vulnerability can be exploited remotely to obtain sensitive information.
Technical details
Attacker with „CREATE TABLE“ privileges can exploit this to read arbitrary bytes server memory. If the attacker also have „INSERT“ and „UPDATE“ privileges to a particular table, the can exploit this to update other columns in this table
Ursprüngliche Informationshinweise
CVE Liste
- CVE-2018-10915 warning
- CVE-2018-10925 warning
Mehr erfahren
Informieren Sie sich über die Statistiken der in Ihrer Region verbreiteten Sicherheitslücken statistics.securelist.com
Sie haben einen Fehler in der Beschreibung der Schwachstelle gefunden? Mitteilen!