CVE-2010-3433

Description

The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.

Risk Information

Base Score
10.0
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.684

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2010-3433,CVE-2016-0768 are affected in Postgresql 9.0Windows
Vulnerabilities CVE-2010-3433 are fixed in PostgreSQL 9.0.1Windows
Vulnerabilities CVE-2010-3433 are fixed in PostgreSQL 8.4.5Windows
Vulnerabilities CVE-2010-3433 are fixed in PostgreSQL 8.3.12Windows
Vulnerabilities CVE-2010-3433 are fixed in PostgreSQL 8.2.18Windows
Vulnerabilities CVE-2010-3433 are fixed in PostgreSQL 8.1.22Windows
Vulnerabilities CVE-2010-3433 are fixed in PostgreSQL 8.0.26Windows
Vulnerabilities CVE-2010-3433 are fixed in PostgreSQL 7.4.30Windows
Vulnerability CVE-2010-3433,CVE-2016-0768 are affected in Postgresql 9.0 (For Linux)Linux
Vulnerabilities CVE-2010-3433 are fixed in PostgreSQL 9.0.1 (For Linux)Linux
Vulnerabilities CVE-2010-3433 are fixed in PostgreSQL 8.4.5 (For Linux)Linux
Vulnerabilities CVE-2010-3433 are fixed in PostgreSQL 8.3.12 (For Linux)Linux
Vulnerabilities CVE-2010-3433 are fixed in PostgreSQL 8.2.18 (For Linux)Linux
Vulnerabilities CVE-2010-3433 are fixed in PostgreSQL 8.1.22 (For Linux)Linux
Vulnerabilities CVE-2010-3433 are fixed in PostgreSQL 8.0.26 (For Linux)Linux
Vulnerabilities CVE-2010-3433 are fixed in PostgreSQL 7.4.30 (For Linux)Linux
CVE-2010-3433NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234