7.5

CVE-2018-10915

A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could bypass client-side connection security features, obtain access to higher privileged connections or potentially cause other impact through SQL injection, by causing the PQescape() functions to malfunction. Postgresql versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 are affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Openstack Version 12
Redhat ≫ Openstack Version 13
Redhat ≫ Virtualization Version 4.0
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Postgresql ≫ Postgresql Version >= 9.3.0 < 9.3.24
Postgresql ≫ Postgresql Version >= 9.4.0 < 9.4.19
Postgresql ≫ Postgresql Version >= 9.5.0 < 9.5.14
Postgresql ≫ Postgresql Version >= 9.6.0 < 9.6.10
Postgresql ≫ Postgresql Version >= 10.0 < 10.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.15% 0.913
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 1.6 5.9
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat 8.5 1.8 6
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-665 Improper Initialization

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

https://access.redhat.com/errata/RHSA-2018:2729
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2511
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2566
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3816
https://access.redhat.com/errata/RHSA-2018:2643
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.html
https://access.redhat.com/errata/RHSA-2018:2565
Third Party Advisory
https://security.gentoo.org/glsa/201810-08
http://www.securityfocus.com/bid/105054
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1041446
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHSA-2018:2557
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2721
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10915
Patch
Third Party Advisory
Issue Tracking
https://lists.debian.org/debian-lts-announce/2018/08/msg00012.html
Third Party Advisory
https://usn.ubuntu.com/3744-1/
Third Party Advisory
https://www.debian.org/security/2018/dsa-4269
Third Party Advisory
https://www.postgresql.org/about/news/1878/
Vendor Advisory