CVE-2017-16082
07.06.2018, 02:29
A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.
Vendor | Product | Version |
---|---|---|
node-postgres | pg | 2.0.0 ≤ 𝑥 < 2.11.2 |
node-postgres | pg | 3.0.0 ≤ 𝑥 < 3.6.4 |
node-postgres | pg | 4.0.0 ≤ 𝑥 < 4.5.7 |
node-postgres | pg | 5.0.0 < 𝑥 < 5.2.1 |
node-postgres | pg | 6.0.0 ≤ 𝑥 < 6.4.2 |
node-postgres | pg | 7.0.0 ≤ 𝑥 < 7.1.2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases