CVE-2023-39417
11.08.2023, 13:15
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.
Vendor | Product | Version |
---|---|---|
postgresql | postgresql | 11.0 ≤ 𝑥 < 11.21 |
postgresql | postgresql | 12.0 ≤ 𝑥 < 12.16 |
postgresql | postgresql | 13.0 ≤ 𝑥 < 13.12 |
postgresql | postgresql | 14.0 ≤ 𝑥 < 14.9 |
postgresql | postgresql | 15.0 ≤ 𝑥 < 15.4 |
redhat | software_collections | - |
redhat | enterprise_linux | 8.0 |
redhat | enterprise_linux | 9.0 |
debian | debian_linux | 8.0 |
debian | debian_linux | 11.0 |
debian | debian_linux | 12.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
postgresql-10 |
| ||||||||||||||||||
postgresql-12 |
| ||||||||||||||||||
postgresql-14 |
| ||||||||||||||||||
postgresql-15 |
| ||||||||||||||||||
postgresql-9.1 |
| ||||||||||||||||||
postgresql-9.3 |
| ||||||||||||||||||
postgresql-9.5 |
|
References