postgresql: TYPE in pg_temp executes arbitrary SQL during SECURITY DEFINER execution
Published Oct 29, 2019
8.8
HIGHCVSS 3.1
EPSS 2.19%
Description
A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 where arbitrary SQL statements can be executed given a suitable SECURITY DEFINER function. An attacker, with EXECUTE permission on the function, can execute arbitrary SQL as the owner of the function.
Affected products
-
- Version all 10.x before 10.10StatusaffectedConstraints-
- Version all 11.x before 11.5StatusaffectedConstraints-
- Version all 9.4.x before 9.4.24StatusaffectedConstraints-
- Version all 9.5.x before 9.5.19StatusaffectedConstraints-
- Version all 9.6.x before 9.6.15StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| PostgreSQL | PostgreSQL | n/a |
|
- ≥ 9.4.0 · < 9.4.24
- ≥ 9.5.0 · < 9.5.19
- ≥ 9.6.0 · < 9.6.15
- ≥ 10.0 · < 10.10
- ≥ 11.0 · < 11.5
No data.
Red Hat Enterprise Linux 7
postgresql-0:9.2.24-6.el7_9
Fixed · RHSA-2021:1512
Red Hat Enterprise Linux 8
postgresql:10-8020020200825115746.4cda2c84
Fixed · RHSA-2020:3669
Red Hat Enterprise Linux 8
postgresql:9.6-8030020201201133334.229f0a1c
Fixed · RHSA-2020:5619
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
postgresql:10-8000020201214113918.f8e95b4e
Fixed · RHSA-2020:5664
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
postgresql:9.6-8000020201214122017.f8e95b4e
Fixed · RHSA-2020:5661
Red Hat Enterprise Linux 8.1 Extended Update Support
postgresql:10-8010020201214112129.c27ad7f8
Fixed · RHSA-2021:0166
Red Hat Enterprise Linux 8.1 Extended Update Support
postgresql:9.6-8010020201214134447.c27ad7f8
Fixed · RHSA-2021:0167
Red Hat Enterprise Linux 8.2 Extended Update Support
postgresql:9.6-8020020201201133334.4cda2c84
Fixed · RHSA-2021:0164
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-postgresql10-postgresql-0:10.12-2.el7
Fixed · RHSA-2020:0980
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-postgresql96-postgresql-0:9.6.19-1.el7
Fixed · RHSA-2020:4295
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-postgresql10-postgresql-0:10.12-2.el7
Fixed · RHSA-2020:0980
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-postgresql10-postgresql-0:10.12-2.el7
Fixed · RHSA-2020:0980
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-postgresql96-postgresql-0:9.6.19-1.el7
Fixed · RHSA-2020:4295
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-postgresql10-postgresql-0:10.12-2.el7
Fixed · RHSA-2020:0980
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-postgresql96-postgresql-0:9.6.19-1.el7
Fixed · RHSA-2020:4295
Red Hat Decision Manager 7
postgresql
Not affected
Red Hat Enterprise Linux 5
postgresql
Out of support scope
Red Hat Enterprise Linux 6
postgresql
Out of support scope
Red Hat Enterprise Linux 8
libpq
Not affected
Red Hat Process Automation 7
postgresql
Not affected
Red Hat Satellite 5
rh-postgresql95-postgresql
Out of support scope
Red Hat Storage 3
rhevm-dependencies
Not affected
Red Hat Virtualization 4
rh-postgresql10-postgresql
Will not fix
Red Hat Virtualization 4
rh-postgresql95-postgresql
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | postgresql-0:9.2.24-6.el7_9 | Fixed | RHSA-2021:1512 |
| Red Hat Enterprise Linux 8 | postgresql:10-8020020200825115746.4cda2c84 | Fixed | RHSA-2020:3669 |
| Red Hat Enterprise Linux 8 | postgresql:9.6-8030020201201133334.229f0a1c | Fixed | RHSA-2020:5619 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | postgresql:10-8000020201214113918.f8e95b4e | Fixed | RHSA-2020:5664 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | postgresql:9.6-8000020201214122017.f8e95b4e | Fixed | RHSA-2020:5661 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | postgresql:10-8010020201214112129.c27ad7f8 | Fixed | RHSA-2021:0166 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | postgresql:9.6-8010020201214134447.c27ad7f8 | Fixed | RHSA-2021:0167 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | postgresql:9.6-8020020201201133334.4cda2c84 | Fixed | RHSA-2021:0164 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-postgresql10-postgresql-0:10.12-2.el7 | Fixed | RHSA-2020:0980 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-postgresql96-postgresql-0:9.6.19-1.el7 | Fixed | RHSA-2020:4295 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-postgresql10-postgresql-0:10.12-2.el7 | Fixed | RHSA-2020:0980 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-postgresql10-postgresql-0:10.12-2.el7 | Fixed | RHSA-2020:0980 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-postgresql96-postgresql-0:9.6.19-1.el7 | Fixed | RHSA-2020:4295 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-postgresql10-postgresql-0:10.12-2.el7 | Fixed | RHSA-2020:0980 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-postgresql96-postgresql-0:9.6.19-1.el7 | Fixed | RHSA-2020:4295 |
| Red Hat Decision Manager 7 | postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 5 | postgresql | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | postgresql | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | libpq | Not affected | n/a |
| Red Hat Process Automation 7 | postgresql | Not affected | n/a |
| Red Hat Satellite 5 | rh-postgresql95-postgresql | Out of support scope | n/a |
| Red Hat Storage 3 | rhevm-dependencies | Not affected | n/a |
| Red Hat Virtualization 4 | rh-postgresql10-postgresql | Will not fix | n/a |
| Red Hat Virtualization 4 | rh-postgresql95-postgresql | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Virtualization Management Appliance included affected versions of postgresql, however no custom SECURITY DEFINER functions are declared so this vulnerability can not be exploited in the default configuration.
Red Hat mitigation
If your use case requires SECURITY DEFINER functions, please follow the advice below to write them safely so they do not rely on search_path and restrict the set of users which can access them. https://www.postgresql.org/docs/devel/sql-createfunction.html#SQL-CREATEFUNCTION-SECURITY
References (8)
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/security/cve/CVE-2019-10208 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1734416 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10208 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-2225 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10208
- https://www.cve.org/CVERecord?id=CVE-2019-10208
- https://www.postgresql.org/about/news/1960/ x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.html | vendor-advisoryx_refsource_SUSE | |
| https://access.redhat.com/security/cve/CVE-2019-10208 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1734416 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10208 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-2225 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-10208 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-10208 | ||
| https://www.postgresql.org/about/news/1960/ | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.