Latest postgresql postgresql Vulnerabilities

PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL
PostgreSQL PostgreSQL>=12.0<12.18
PostgreSQL PostgreSQL>=13.0<13.14
PostgreSQL PostgreSQL>=14.0<14.11
PostgreSQL PostgreSQL>=15.0<15.6
ubuntu/postgresql-16<16.2
ubuntu/postgresql-15<15.6-0ubuntu0.23.10.1
and 14 more
Postgresql: role pg_signal_backend can signal certain superuser processes.
ubuntu/postgresql-14<14.10-0ubuntu0.22.04.1
ubuntu/postgresql-14<14.10
ubuntu/postgresql-12<12.17-0ubuntu0.20.04.1
ubuntu/postgresql-12<12.17
ubuntu/postgresql-10<10.23-0ubuntu0.18.04.2+
ubuntu/postgresql-9.5<9.5.25-0ubuntu0.16.04.1+
and 56 more
Postgresql: buffer overrun from integer overflow in array modification
ubuntu/postgresql-14<14.10
ubuntu/postgresql-14<14.10-0ubuntu0.22.04.1
ubuntu/postgresql-12<12.17-0ubuntu0.20.04.1
ubuntu/postgresql-12<12.17
ubuntu/postgresql-10<10.23-0ubuntu0.18.04.2+
ubuntu/postgresql-9.5<9.5.25-0ubuntu0.16.04.1+
and 63 more
Postgresql: memory disclosure in aggregate function calls
ubuntu/postgresql-14<14.10-0ubuntu0.22.04.1
ubuntu/postgresql-14<14.10
ubuntu/postgresql-12<12.17-0ubuntu0.20.04.1
ubuntu/postgresql-12<12.17
ubuntu/postgresql-10<10.23-0ubuntu0.18.04.2+
ubuntu/postgresql-15<15.5
and 55 more
** DISPUTED ** An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals. NOTE: this is disputed by the vendor because untrusted us...
PostgreSQL PostgreSQL=12.2
Postgresql: merge fails to enforce update or select row security policies
ubuntu/postgresql-15<15.4-1
ubuntu/postgresql-15<15.4-0ubuntu0.23.04.1
ubuntu/postgresql-15<15.4-1ubuntu1
redhat/postgresql<15.4
PostgreSQL PostgreSQL>=15.0<15.4
Redhat Enterprise Linux=8.0
and 5 more
Postgresql: extension script @substitutions@ within quoting allow sql injection
ubuntu/postgresql-14<14.9-0ubuntu0.22.04.1
ubuntu/postgresql-12<12.16-0ubuntu0.20.04.1
ubuntu/postgresql-9.5<9.5.25-0ubuntu0.16.04.1+
ubuntu/postgresql-15<15.4-1
ubuntu/postgresql-15<15.4-0ubuntu0.23.04.1
ubuntu/postgresql-15<15.4-1ubuntu1
and 19 more
aiven-extras is a PostgreSQL extension. Versions prior to 1.1.9 contain a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras pack...
Aiven Aiven<1.1.9
PostgreSQL PostgreSQL>=10.0<=10.22
PostgreSQL PostgreSQL>=11.0<=11.7
PostgreSQL PostgreSQL>=12.0<=12.12
PostgreSQL PostgreSQL>=13.0<=13.8
PostgreSQL PostgreSQL>=14.0<=14.5
and 6 more
CVE-2023-2454: CREATE SCHEMA ... schema_element defeats protective search_path changes. Versions Affected: 11 - 15. This problem is quite old. This enabled an attacker having database-level CREATE p...
redhat/PostgreSQL<15.3
redhat/PostgreSQL<14.8
redhat/PostgreSQL<13.11
redhat/PostgreSQL<12.15
redhat/PostgreSQL<11.20
PostgreSQL PostgreSQL>=11.0<11.20
and 17 more
CVE-2023-2455: Row security policies disregard user ID changes after inlining. Versions Affected: 11 - 15. This problem is quite old. While <a href="https://access.redhat.com/security/cve/CVE-2016-2...
redhat/PostgreSQL<15.3
redhat/PostgreSQL<14.8
redhat/PostgreSQL<13.11
redhat/PostgreSQL<12.15
redhat/PostgreSQL<11.20
PostgreSQL PostgreSQL>=11.0<11.20
and 16 more
A modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. When a libpq client application has a Kerberos credential cache and doesn'...
redhat/postgresql<5.2
redhat/postgresql<14.7
redhat/postgresql<13.10
redhat/postgresql<12.14
redhat/postgresql<11.19
IBM Cloud Pak for Business Automation<=V23.0.1 - V23.0.1-IF001
and 11 more
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use...
PostgreSQL PostgreSQL>=9.6.0<9.6.24
PostgreSQL PostgreSQL>=10.0<10.19
PostgreSQL PostgreSQL>=11.0<11.14
PostgreSQL PostgreSQL>=12.0<12.9
PostgreSQL PostgreSQL>=13.0<13.5
PostgreSQL PostgreSQL=14.0
A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an...
redhat/postgresql<14.5
redhat/postgresql<13.8
redhat/postgresql<12.12
redhat/postgresql<11.17
redhat/postgresql<10.22
PostgreSQL PostgreSQL>=10.0<10.22
and 11 more
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH...
redhat/postgresql<14.3
redhat/postgresql<13.7
redhat/postgresql<12.11
redhat/postgresql<11.16
redhat/postgresql<10.21
PostgreSQL PostgreSQL>=10.0<10.21
and 4 more
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. The problem occurs in the following code in server/service/system/sys_auto_co...
Gin-vue-admin Project Gin-vue-admin<2.5.1
PostgreSQL PostgreSQL
PostgreSQL is vulnerable to a man-in-the-middle attack, caused by improper validation of user-supplied input by libpq. A remote attacker could exploit this vulnerability to launch a man-in-the-middle ...
IBM Spectrum Protect Plus<=10.1.0.0-10.1.9.2
redhat/postgresql<9.6.24
redhat/postgresql<10.19
redhat/postgresql<11.14
redhat/postgresql<12.9
redhat/postgresql<13.5
and 7 more
PostgreSQL is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements when the server is configured to use trust authentication with a clientcert requirement or to u...
IBM QRadar SIEM<=7.5.0 GA
IBM QRadar SIEM<=7.4.3 GA - 7.4.3 FP4
IBM QRadar SIEM<=7.3.3 GA - 7.3.3 FP10
redhat/postgresql<9.6.24
redhat/postgresql<10.19
redhat/postgresql<11.14
and 15 more
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The a...
redhat/postgresql<13.4
redhat/postgresql<12.8
redhat/postgresql<11.13
PostgreSQL PostgreSQL>=11.0<11.13
PostgreSQL PostgreSQL>=12.0<12.8
PostgreSQL PostgreSQL>=13.0<13.4
and 7 more
PostgreSQL could allow a remote authenticated attacker to obtain sensitive information, caused by an error when using an UPDATE…RETURNING command on a purpose-crafted table. An attacker could exploit ...
IBM Security Verify Access<=10.0.0
redhat/postgresql<13.3
redhat/postgresql<12.7
redhat/postgresql<11.12
PostgreSQL PostgreSQL>=11.0<11.12
PostgreSQL PostgreSQL>=12.0<12.7
and 2 more
PostgreSQL could allow a remote authenticated attacker to obtain sensitive information, caused by a memory disclosure vulnerability when using an INSERT … ON CONFLICT … DO UPDATE command on a purpose-...
IBM Security Verify Access<=10.0.0
redhat/postgresql<13.3
redhat/postgresql<12.7
redhat/postgresql<11.12
redhat/postgresql<10.17
redhat/postgresql<9.6.22
and 5 more
PostgreSQL could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an integer overflow while modifying certain SQL array values. By sending a specially-crafted r...
IBM Security Verify Access<=10.0.0
redhat/postgresql<13.3
redhat/postgresql<12.7
redhat/postgresql<11.12
redhat/postgresql<10.17
redhat/postgresql<9.6.22
and 9 more
A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat f...
redhat/postgresql<13.2
PostgreSQL PostgreSQL>=13.0<13.2
Redhat Software Collections
Redhat Enterprise Linux=7.0
Redhat Enterprise Linux=8.0
Fedoraproject Fedora=33
PostgreSQL could allow a remote authenticated attacker to obtain sensitive information, caused by a flaw in the error messages. By sending a specially-crafted query, an attacker could exploit this vul...
IBM Security Verify Governance<=10.0
redhat/postgresql<13.2
redhat/postgresql<12.6
redhat/postgresql<11.11
PostgreSQL PostgreSQL<11.11
PostgreSQL PostgreSQL>=12.0<12.6
and 3 more
A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If an interactive psql session uses \...
redhat/libpq<0:12.5-1.el8_3
redhat/libpq<0:12.5-1.el8_0
redhat/libpq<0:12.5-2.el8_1
redhat/libpq<0:12.5-1.el8_2
redhat/rh-postgresql10-postgresql<0:10.15-1.el7
redhat/rh-postgresql12-postgresql<0:12.5-1.el7
and 13 more
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least...
redhat/postgresql<0:9.2.24-6.el7_9
redhat/rh-postgresql10-postgresql<0:10.15-1.el7
redhat/rh-postgresql12-postgresql<0:12.5-1.el7
redhat/postgresql<13.1
redhat/postgresql<12.5
redhat/postgresql<11.10
and 10 more
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only...
redhat/postgresql<0:9.2.24-6.el7_9
redhat/libpq<0:12.5-1.el8_3
redhat/libpq<0:12.5-1.el8_0
redhat/libpq<0:12.5-2.el8_1
redhat/libpq<0:12.5-1.el8_2
redhat/rh-postgresql10-postgresql<0:10.15-1.el7
and 14 more
The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working ...
PostgreSQL PostgreSQL>=9.5<9.5.22
PostgreSQL PostgreSQL>=9.6<9.6.18
PostgreSQL PostgreSQL>=10.0<10.13
PostgreSQL PostgreSQL>=11.0<11.8
PostgreSQL PostgreSQL>=12.0<12.3
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into exec...
redhat/rh-postgresql96-postgresql<0:9.6.19-1.el7
redhat/rh-postgresql10-postgresql<0:10.14-1.el7
redhat/rh-postgresql12-postgresql<0:12.4-1.el7
redhat/rhvm-appliance<0:4.4-20210310.0.el8e
redhat/postgresql<12.4
redhat/postgresql<11.9
and 22 more
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in a...
redhat/rh-postgresql10-postgresql<0:10.14-1.el7
redhat/rh-postgresql12-postgresql<0:12.4-1.el7
redhat/rhvm-appliance<0:4.4-20210310.0.el8e
redhat/postgresql<12.4
redhat/postgresql<11.9
redhat/postgresql<10.14
and 11 more
A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to p...
redhat/rh-postgresql10-postgresql<0:10.12-2.el7
redhat/rh-postgresql96-postgresql<0:9.6.19-1.el7
redhat/rh-postgresql12-postgresql<0:12.4-1.el7
IBM Data Risk Manager<=2.0.6
redhat/PostgreSQL<12.2
redhat/PostgreSQL<11.7
and 9 more
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote att...
PostgreSQL PostgreSQL<9.0.19
PostgreSQL PostgreSQL>=9.1.0<9.1.15
PostgreSQL PostgreSQL>=9.2.0<9.2.10
PostgreSQL PostgreSQL>=9.3.0<9.3.6
PostgreSQL PostgreSQL>=9.4.0<9.4.1
Debian Debian Linux=7.0
and 1 more
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (c...
PostgreSQL PostgreSQL<9.0.19
PostgreSQL PostgreSQL>=9.1.0<9.1.15
PostgreSQL PostgreSQL>=9.2.0<9.2.10
PostgreSQL PostgreSQL>=9.3.0<9.3.6
PostgreSQL PostgreSQL>=9.4.0<9.4.1
Debian Debian Linux=7.0
and 1 more
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to caus...
PostgreSQL PostgreSQL<9.0.19
PostgreSQL PostgreSQL>=9.1.0<9.1.15
PostgreSQL PostgreSQL>=9.2.0<9.2.10
PostgreSQL PostgreSQL>=9.3.0<9.3.6
PostgreSQL PostgreSQL>=9.4.0<9.4.1
Debian Debian Linux=7.0
and 1 more
Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a...
PostgreSQL PostgreSQL<9.0.19
PostgreSQL PostgreSQL>=9.1.0<9.1.15
PostgreSQL PostgreSQL>=9.2.0<9.2.10
PostgreSQL PostgreSQL>=9.3.0<9.3.6
PostgreSQL PostgreSQL>=9.4.0<9.4.1
Microsoft Windows
and 2 more
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constra...
PostgreSQL PostgreSQL<9.0.19
PostgreSQL PostgreSQL>=9.1.0<9.1.15
PostgreSQL PostgreSQL>=9.2.0<9.2.10
PostgreSQL PostgreSQL>=9.3.0<9.3.6
PostgreSQL PostgreSQL>=9.4.0<9.4.1
Debian Debian Linux=7.0
and 1 more
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows ...
PostgreSQL PostgreSQL<9.0.20
PostgreSQL PostgreSQL>=9.1<9.1.16
PostgreSQL PostgreSQL>=9.2<9.2.11
PostgreSQL PostgreSQL>=9.3<9.3.7
PostgreSQL PostgreSQL>=9.4<9.4.2
Debian Debian Linux=7.0
and 6 more
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which m...
PostgreSQL PostgreSQL<9.0.20
PostgreSQL PostgreSQL>=9.1<9.1.16
PostgreSQL PostgreSQL>=9.2<9.2.11
PostgreSQL PostgreSQL>=9.3<9.3.7
PostgreSQL PostgreSQL>=9.4<9.4.2
Debian Debian Linux=7.0
and 6 more
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.
PostgreSQL PostgreSQL<9.4.24
PostgreSQL PostgreSQL>=9.5.0<9.5.19
PostgreSQL PostgreSQL>=9.6.0<9.6.15
PostgreSQL PostgreSQL>=10.0<10.10
PostgreSQL PostgreSQL>=11.0<11.5
Microsoft Windows
Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.
PostgreSQL PostgreSQL>=11.0<11.5
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file.
PostgreSQL PostgreSQL<9.4.24
PostgreSQL PostgreSQL>=9.5.0<9.5.19
PostgreSQL PostgreSQL>=9.6.0<9.6.15
PostgreSQL PostgreSQL>=10.0<10.10
PostgreSQL PostgreSQL>=11.0<11.5
Microsoft Windows
A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned table, an attacker can read arbitrary bytes of server memory. In the default config...
PostgreSQL PostgreSQL>=11.0<11.3
A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 where arbitrary SQL statements can be executed given ...
redhat/postgresql<0:9.2.24-6.el7_9
redhat/rh-postgresql10-postgresql<0:10.12-2.el7
redhat/rh-postgresql96-postgresql<0:9.6.19-1.el7
redhat/postgresql<11.5
redhat/postgresql<10.10
redhat/postgresql<9.6.15
and 7 more
Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating syste...
redhat/libpq<0:12.1-3.el8
redhat/rh-postgresql10-postgresql<0:10.12-2.el7
redhat/PostgreSQL<10.9
redhat/PostgreSQL<11.4
PostgreSQL PostgreSQL>=10.0<10.9
PostgreSQL PostgreSQL>=11.0<11.4
and 5 more
A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statist...
redhat/rh-postgresql10-postgresql<0:10.12-2.el7
redhat/rh-postgresql96-postgresql<0:9.6.19-1.el7
redhat/postgresql<11.3
redhat/postgresql<10.8
redhat/postgresql<9.6.13
redhat/postgresql<9.5.17
and 5 more
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the A...
PostgreSQL PostgreSQL<9.4.22
PostgreSQL PostgreSQL>=9.5.0<9.5.17
PostgreSQL PostgreSQL>=9.6.0<9.6.13
PostgreSQL PostgreSQL>=10.0<10.8
PostgreSQL PostgreSQL>=11.0<11.3
Microsoft Windows
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of ...
PostgreSQL PostgreSQL<9.4.22
PostgreSQL PostgreSQL>=9.5.0<9.5.17
PostgreSQL PostgreSQL>=9.6.0<9.6.13
PostgreSQL PostgreSQL>=10.0<10.8
PostgreSQL PostgreSQL>=11.0<11.3
Microsoft Windows
** DISPUTED ** In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the ...
IBM Security Verify Governance<=10.0
PostgreSQL PostgreSQL>=9.3<=11.2
>=9.3<=11.2
Postgresql before versions 11.1 and 10.6 are vulnerable to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause...
redhat/postgresql<11.1
redhat/postgresql<10.6
ubuntu/postgresql-10<10.6
ubuntu/postgresql-10<10.6-0ubuntu0.18.04.1
ubuntu/postgresql-10<10.6-0ubuntu0.18.10.1
debian/postgresql-11
and 8 more
It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE"...
ubuntu/postgresql-10<10.5-1
ubuntu/postgresql-10<10.5-0ubuntu0.18.04
ubuntu/postgresql-9.5<9.5.14
ubuntu/postgresql-9.5<9.5.14-0ubuntu0.16.04
debian/postgresql-10
debian/postgresql-9.1
and 10 more
A flaw was found in PostgreSQL. The chief PostgreSQL client library, libpq, does not adequately reset its internal state before each connection attempt. When one requests a connection using a "host" o...
redhat/cfme<0:5.9.6.5-3.el7cf
redhat/cfme-amazon-smartstate<0:5.9.6.5-2.el7cf
redhat/cfme-appliance<0:5.9.6.5-1.el7cf
redhat/cfme-gemset<0:5.9.6.5-2.el7cf
redhat/dbus-api-service<0:1.0.1-3.1.el7cf
redhat/httpd-configmap-generator<0:0.2.2-1.2.el7cf
and 38 more

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203