CVE-2018-10915
Description
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with host or hostaddr connection parameters from untrusted input, attackers could bypass client-side connection security features, obtain access to higher privileged connections or potentially cause other impact through SQL injection, by causing the PQescape() functions to malfunction. Postgresql versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 are affected.
Risk Information
Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.484
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Update PostgressSQL to 9.3.24 | Windows |
| Update PostgressSQL to 9.5.14 | Windows |
| Vulnerabilities CVE-2018-10925,CVE-2018-10915 are fixed in PostgreSQL 10.5 | Windows |
| Vulnerabilities CVE-2018-10925,CVE-2018-10915 are fixed in PostgreSQL 9.6.10 | Windows |
| Vulnerabilities CVE-2018-10925,CVE-2018-10915 are fixed in PostgreSQL 9.5.14 | Windows |
| Vulnerabilities CVE-2018-10915 are fixed in PostgreSQL 9.4.19 | Windows |
| Vulnerabilities CVE-2018-10915 are fixed in PostgreSQL 9.3.24 | Windows |
| object-relational SQL database (USN-3744-1) postgresql-10_10.5-0ubuntu0.18.04_i386.deb | Linux |
| object-relational SQL database (USN-3744-1) postgresql-10_10.5-0ubuntu0.18.04_amd64.deb | Linux |
| object-relational SQL database (USN-3744-1) postgresql-9.3_9.3.24-0ubuntu0.14.04_i386.deb | Linux |
| object-relational SQL database (USN-3744-1) postgresql-9.3_9.3.24-0ubuntu0.14.04_amd64.deb | Linux |
| object-relational SQL database (USN-3744-1) postgresql-9.5_9.5.14-0ubuntu0.16.04_i386.deb | Linux |
| object-relational SQL database (USN-3744-1) postgresql-9.5_9.5.14-0ubuntu0.16.04_amd64.deb | Linux |
| postgresql-9.6 security update(DSA-4269-1) postgresql-9.6_9.6.10-0+deb9u1_amd64.deb | Linux |
| SUSE-SU-2018:3287-1(SUSE Linux Enterprise Server 11-SP4 ) libecpg6-9.4.19-0.23.19.1.i586.rpm | Linux |
| SUSE-SU-2018:3287-1(SUSE Linux Enterprise Server 11-SP4 ) libecpg6-9.4.19-0.23.19.1.x86_64.rpm | Linux |
| SUSE-SU-2018:3287-1(SUSE Linux Enterprise Server 11-SP4 ) libpq5-9.4.19-0.23.19.1.i586.rpm | Linux |
| SUSE-SU-2018:3287-1(SUSE Linux Enterprise Server 11-SP4 ) libpq5-9.4.19-0.23.19.1.x86_64.rpm | Linux |
| SUSE-SU-2018:3287-1(SUSE Linux Enterprise Server 11-SP4 ) libpq5-32bit-9.4.19-0.23.19.1.x86_64.rpm | Linux |
| SUSE-SU-2018:3287-1(SUSE Linux Enterprise Server 11-SP4 ) postgresql94-9.4.19-0.23.19.1.i586.rpm | Linux |
| SUSE-SU-2018:3287-1(SUSE Linux Enterprise Server 11-SP4 ) postgresql94-9.4.19-0.23.19.1.x86_64.rpm | Linux |
| SUSE-SU-2018:3287-1(SUSE Linux Enterprise Server 11-SP4 ) postgresql94-contrib-9.4.19-0.23.19.1.i586.rpm | Linux |
| SUSE-SU-2018:3287-1(SUSE Linux Enterprise Server 11-SP4 ) postgresql94-contrib-9.4.19-0.23.19.1.x86_64.rpm | Linux |
| SUSE-SU-2018:3287-1(SUSE Linux Enterprise Server 11-SP4 ) postgresql94-docs-9.4.19-0.23.19.1.i586.rpm | Linux |
| SUSE-SU-2018:3287-1(SUSE Linux Enterprise Server 11-SP4 ) postgresql94-docs-9.4.19-0.23.19.1.x86_64.rpm | Linux |
| SUSE-SU-2018:3287-1(SUSE Linux Enterprise Server 11-SP4 ) postgresql94-server-9.4.19-0.23.19.1.i586.rpm | Linux |
| SUSE-SU-2018:3287-1(SUSE Linux Enterprise Server 11-SP4 ) postgresql94-server-9.4.19-0.23.19.1.x86_64.rpm | Linux |
| SUSE-SU-2018:3377-1(SUSE Linux Enterprise Desktop 12-SP3 ) postgresql96-9.6.10-3.22.7.x86_64.rpm | Linux |
| SUSE-SU-2018:3377-1(SUSE Linux Enterprise Desktop 12-SP3 ) postgresql96-debuginfo-9.6.10-3.22.7.x86_64.rpm | Linux |
| SUSE-SU-2018:3377-1(SUSE Linux Enterprise Desktop 12-SP3 ) postgresql96-debugsource-9.6.10-3.22.7.x86_64.rpm | Linux |
| SUSE-SU-2018:3377-1(SUSE Linux Enterprise Desktop 12-SP3 ) postgresql96-libs-debugsource-9.6.10-3.22.1.x86_64.rpm | Linux |
| SUSE-SU-2018:3377-1(SUSE Linux Enterprise Server 12-SP3 ) postgresql96-contrib-9.6.10-3.22.7.x86_64.rpm | Linux |
| SUSE-SU-2018:3377-1(SUSE Linux Enterprise Server 12-SP3 ) postgresql96-contrib-debuginfo-9.6.10-3.22.7.x86_64.rpm | Linux |
| SUSE-SU-2018:3377-1(SUSE Linux Enterprise Server 12-SP3 ) postgresql96-docs-9.6.10-3.22.7.noarch.rpm | Linux |
| SUSE-SU-2018:3377-1(SUSE Linux Enterprise Server 12-SP3 ) postgresql96-server-9.6.10-3.22.7.x86_64.rpm | Linux |
| SUSE-SU-2018:3377-1(SUSE Linux Enterprise Server 12-SP3 ) postgresql96-server-debuginfo-9.6.10-3.22.7.x86_64.rpm | Linux |
| Postgresql update (ELSA-2018-2557) postgresql-9.2.24-1.el7_5.x86_64.rpm | Linux |
| Postgresql-contrib update (ELSA-2018-2557) postgresql-contrib-9.2.24-1.el7_5.x86_64.rpm | Linux |
| Postgresql-devel update (ELSA-2018-2557) postgresql-devel-9.2.24-1.el7_5.x86_64.rpm | Linux |
| Postgresql-docs update (ELSA-2018-2557) postgresql-docs-9.2.24-1.el7_5.x86_64.rpm | Linux |
| Postgresql-libs update (ELSA-2018-2557) postgresql-libs-9.2.24-1.el7_5.x86_64.rpm | Linux |
| Postgresql-plperl update (ELSA-2018-2557) postgresql-plperl-9.2.24-1.el7_5.x86_64.rpm | Linux |
| Postgresql-plpython update (ELSA-2018-2557) postgresql-plpython-9.2.24-1.el7_5.x86_64.rpm | Linux |
| Postgresql-pltcl update (ELSA-2018-2557) postgresql-pltcl-9.2.24-1.el7_5.x86_64.rpm | Linux |
| Postgresql-server update (ELSA-2018-2557) postgresql-server-9.2.24-1.el7_5.x86_64.rpm | Linux |
| Postgresql-static update (ELSA-2018-2557) postgresql-static-9.2.24-1.el7_5.x86_64.rpm | Linux |
| Postgresql-test update (ELSA-2018-2557) postgresql-test-9.2.24-1.el7_5.x86_64.rpm | Linux |
| Postgresql-upgrade update (ELSA-2018-2557) postgresql-upgrade-9.2.24-1.el7_5.x86_64.rpm | Linux |
| Postgresql update (ELSA-2018-2557) postgresql-9.2.24-1.el7_5.i686.rpm | Linux |
| Postgresql-devel update (ELSA-2018-2557) postgresql-devel-9.2.24-1.el7_5.i686.rpm | Linux |
| Postgresql-libs update (ELSA-2018-2557) postgresql-libs-9.2.24-1.el7_5.i686.rpm | Linux |
| Postgresql-static update (ELSA-2018-2557) postgresql-static-9.2.24-1.el7_5.i686.rpm | Linux |
| Update PostgressSQL to 9.3.24 (For Linux) | Linux |
| Update PostgressSQL to 9.5.14 (For Linux) | Linux |
| Vulnerabilities CVE-2018-10925,CVE-2018-10915 are fixed in PostgreSQL 10.5 (For Linux) | Linux |
| Vulnerabilities CVE-2018-10925,CVE-2018-10915 are fixed in PostgreSQL 9.6.10 (For Linux) | Linux |
| Vulnerabilities CVE-2018-10925,CVE-2018-10915 are fixed in PostgreSQL 9.5.14 (For Linux) | Linux |
| Vulnerabilities CVE-2018-10915 are fixed in PostgreSQL 9.4.19 (For Linux) | Linux |
| Vulnerabilities CVE-2018-10915 are fixed in PostgreSQL 9.3.24 (For Linux) | Linux |
| Postgresql-server update (ELSA-2024-10882) postgresql-server-9.2.24-9.0.3.el7_9.x86_64.rpm | Linux |
| Postgresql-pltcl update (ELSA-2024-10882) postgresql-pltcl-9.2.24-9.0.3.el7_9.x86_64.rpm | Linux |
| Postgresql-plpython update (ELSA-2024-10882) postgresql-plpython-9.2.24-9.0.3.el7_9.x86_64.rpm | Linux |
| Postgresql-plperl update (ELSA-2024-10882) postgresql-plperl-9.2.24-9.0.3.el7_9.x86_64.rpm | Linux |
| Postgresql-libs update (ELSA-2024-10882) postgresql-libs-9.2.24-9.0.3.el7_9.x86_64.rpm | Linux |
| Postgresql-libs update (ELSA-2024-10882) postgresql-libs-9.2.24-9.0.3.el7_9.i686.rpm | Linux |
| Postgresql-docs update (ELSA-2024-10882) postgresql-docs-9.2.24-9.0.3.el7_9.x86_64.rpm | Linux |
| Postgresql-devel update (ELSA-2024-10882) postgresql-devel-9.2.24-9.0.3.el7_9.x86_64.rpm | Linux |
| Postgresql-devel update (ELSA-2024-10882) postgresql-devel-9.2.24-9.0.3.el7_9.i686.rpm | Linux |
| Postgresql-contrib update (ELSA-2024-10882) postgresql-contrib-9.2.24-9.0.3.el7_9.x86_64.rpm | Linux |
| Postgresql update (ELSA-2024-10882) postgresql-9.2.24-9.0.3.el7_9.x86_64.rpm | Linux |
| Postgresql update (ELSA-2024-10882) postgresql-9.2.24-9.0.3.el7_9.i686.rpm | Linux |
| Postgresql-test update (ELSA-2024-10882) postgresql-test-9.2.24-9.0.3.el7_9.x86_64.rpm | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234