postgresql: Command injection via "COPY TO/FROM PROGRAM" function
Published Apr 1, 2019
7.2
HIGHCVSS 3.0
EPSS 91.66%
Description
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.
Affected products
No data.
- ≥ 9.3 · ≤ 11.2
No data.
CloudForms Management Engine 5
postgresql96
Not affected
Red Hat Ansible Tower 3
postgresql96-libs
Not affected
Red Hat Enterprise Linux 5
postgresql
Not affected
Red Hat Enterprise Linux 6
postgresql
Not affected
Red Hat Enterprise Linux 7
postgresql
Not affected
Red Hat Enterprise Linux 8
libpq
Not affected
Red Hat Enterprise Linux 8
postgresql
Not affected
Red Hat Satellite 5
rh-postgresql95-postgresql
Not affected
Red Hat Software Collections
rh-postgresql10-postgresql
Not affected
Red Hat Software Collections
rh-postgresql95-postgresql
Not affected
Red Hat Software Collections
rh-postgresql96-postgresql
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | postgresql96 | Not affected | n/a |
| Red Hat Ansible Tower 3 | postgresql96-libs | Not affected | n/a |
| Red Hat Enterprise Linux 5 | postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 6 | postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 7 | postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 8 | libpq | Not affected | n/a |
| Red Hat Enterprise Linux 8 | postgresql | Not affected | n/a |
| Red Hat Satellite 5 | rh-postgresql95-postgresql | Not affected | n/a |
| Red Hat Software Collections | rh-postgresql10-postgresql | Not affected | n/a |
| Red Hat Software Collections | rh-postgresql95-postgresql | Not affected | n/a |
| Red Hat Software Collections | rh-postgresql96-postgresql | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The PostgreSQL Project does not consider this to be a vulnerability. By design, database super users have full rights to the context that PostgreSQL executes within, including reading & writing all files and code execution. See External References for more details. Red Hat Product Security concurs with upstream's assessment that this is not a vulnerability. Customers are advised to follow best practice when configuring PostgreSQL, which includes allocating only the minimum privileges to users. Super user privileges in particular must be very carefully controlled.
References (14)
- http://packetstormsecurity.com/files/152757/PostgreSQL-COPY-FROM-PROGRAM-Command-Execution.html Third Party Advisory
- http://packetstormsecurity.com/files/166540/PostgreSQL-11.7-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/171722/PostgreSQL-9.6.1-Remote-Code-Execution.html
- https://access.redhat.com/security/cve/CVE-2019-9193 Vendor Advisory
- https://blog.hagander.net/when-a-vulnerability-is-not-a-vulnerability-244/ Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1695982 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-18570 Advisory
- https://medium.com/greenwolf-security/authenticated-arbitrary-command-execution-on-postgresql-9-3-latest-cd18945914d5 ExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-9193
- https://paquier.xyz/postgresql-2/postgres-9-3-feature-highlight-copy-tofrom-program/ Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190502-0003/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-9193
- https://www.postgresql.org/about/news/1935/
- https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/authenticated-arbitrary-command-execution-on-postgresql-9-3/ Third Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data