Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HPostgreSQL
APPPostgresql14.0 – 14.21 (excl.)15.0 – 15.16 (excl.)16.0 – 16.12 (excl.)17.0 – 17.8 (excl.)18.0 – 18.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
References
Related vulnerabilities
CVE-2015-0244CRITICAL9.8PL ✓same product
SQL injection w PostgreSQL przez błąd synchronizacji protokołu
CVE-2015-3166CRITICAL9.8PL ✓same product
PostgreSQL: błąd obsługi błędów systemowych w implementacji snprintf
CVE-2019-10211CRITICAL9.8PL ✓same product
PostgreSQL Windows Installer — wykonanie kodu z niezabezpieczonego katalogu (OpenSSL)
CVE-2018-16850CRITICAL9.8PL ✓same product
SQL injection w PostgreSQL via CREATE TRIGGER — wykonanie kodu z uprawnieniami superusera
CVE-2018-1115CRITICAL9.1PL ✓same product
PostgreSQL adminpack: brak kontroli ACL w funkcji pg_logfile_rotate()