CVE-2020-14350
24.08.2020, 13:15
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.Enginsight
| Vendor | Product | Version |
|---|---|---|
| postgresql | postgresql | 9.5 ≤ 𝑥 < 9.5.23 |
| postgresql | postgresql | 9.6 ≤ 𝑥 < 9.6.19 |
| postgresql | postgresql | 10.0 ≤ 𝑥 < 10.14 |
| postgresql | postgresql | 11.0 ≤ 𝑥 < 11.9 |
| postgresql | postgresql | 12.0 ≤ 𝑥 < 12.4 |
| debian | debian_linux | 9.0 |
| opensuse | leap | 15.1 |
| opensuse | leap | 15.2 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 20.04 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| postgresql-10 |
| ||||||||||||||||||||||||
| postgresql-12 |
| ||||||||||||||||||||||||
| postgresql-9.1 |
| ||||||||||||||||||||||||
| postgresql-9.3 |
| ||||||||||||||||||||||||
| postgresql-9.5 |
|
Common Weakness Enumeration
References