CVE-2019-10208
Published: 08 August 2019
A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 where arbitrary SQL statements can be executed given a suitable SECURITY DEFINER function. An attacker, with EXECUTE permission on the function, can execute arbitrary SQL as the owner of the function.
From the Ubuntu security team
Tom Lane discovered that PostgreSQL did not properly restrict functions declared as "SECURITY DEFINER". An attacker could use this to execute arbitrary SQL with the permissions of the function owner.
Priority
CVSS 3 base score: 8.8
Status
Package | Release | Status |
---|---|---|
postgresql-10 Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Released
(10.10-0ubuntu0.18.04.1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
postgresql-11 Launchpad, Ubuntu, Debian |
Upstream |
Released
(11.5-1)
|
Ubuntu 20.04 LTS (Focal Fossa) |
Released
(11.5-1)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Does not exist
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
postgresql-9.1 Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Does not exist
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
postgresql-9.3 Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Does not exist
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Does not exist
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Ignored
|
|
postgresql-9.5 Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 20.04 LTS (Focal Fossa) |
Does not exist
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Does not exist
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(9.5.19-0ubuntu0.16.04.1)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
Notes
Author | Note |
---|---|
leosilva | since 9.3 is not supported anymore by upstream and for now we don't have how to patch it I'm marking it as ignored. |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10208
- https://www.postgresql.org/about/news/1960/
- https://usn.ubuntu.com/usn/usn-4090-1
- NVD
- Launchpad
- Debian