7.3

CVE-2020-14350

It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Postgresql ≫ Postgresql Version >= 9.5 < 9.5.23
Postgresql ≫ Postgresql Version >= 9.6 < 9.6.19
Postgresql ≫ Postgresql Version >= 10.0 < 10.14
Postgresql ≫ Postgresql Version >= 11.0 < 11.9
Postgresql ≫ Postgresql Version >= 12.0 < 12.4
Debian ≫ Debian Linux Version 9.0
Opensuse ≫ Leap Version 15.1
Opensuse ≫ Leap Version 15.2
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.406
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
NIST 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
CWE-426 Untrusted Search Path

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00044.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00049.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00050.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00003.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00008.html
Third Party Advisory
Mailing List
https://security.gentoo.org/glsa/202008-13
Third Party Advisory
https://security.netapp.com/advisory/ntap-20200918-0002/
Third Party Advisory
https://usn.ubuntu.com/4472-1/
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1865746
Third Party Advisory
Issue Tracking
https://lists.debian.org/debian-lts-announce/2020/08/msg00028.html
Third Party Advisory
Mailing List