KLA10790
Multiple vulnerabilities in PostgreSQL
Обновлено: 17/06/2019
Дата обнаружения
11/04/2016
Уровень угрозы
Critical
Описание

Multiple serious vulnerabilities have been found in PostgreSQL. Malicious users can exploit these vulnerabilities to bypass security restrictions, obtain sensitive information or cause denial of service.

Below is a complete list of vulnerabilities

  1. An unknown vulnerability can be exploited via a specially designed index page to bypass security restrictions and obtain sensitive information or cause denial of service;
  2. An improper row-security status maintenance can be exploited via session manipulations to bypass security restrictions.

Technical details

Vulnerability (1) related to brin_page_type and brin_metapage_info functions in the pageinspect extension. This vulnerability can be exploited via a specially designed bytea value in a BRIN index page.

Vulnerability (2) related to maintenance of row-security status in cached plans. This vulnerability can be exploited via leveraging session that perform queries as more than one role.

Пораженные продукты

PostgreSQL 9.5 versions earlier than 9.5.2

Решение

Update to the latest version
Get PostgreSQL

Первичный источник обнаружения
Security fixes note
Оказываемое влияние
?
OSI 
[?]

DoS 
[?]

SB 
[?]
Связанные продукты
PostgreSQL
CVE-IDS
CVE-2016-21935.0Critical
CVE-2016-30658.5Critical