漏洞描述
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
usn.ubuntu.comhttps://usn.ubuntu.com/3589-1/↗access.redhat.comhttps://access.redhat.com/errata/RHSA-2018:2566↗bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=1547044↗access.redhat.comhttps://access.redhat.com/errata/RHSA-2018:3816↗access.redhat.comhttps://access.redhat.com/errata/RHSA-2018:2511↗www.postgresql.orghttps://www.postgresql.org/about/news/1834/↗www.securityfocus.comhttp://www.securityfocus.com/bid/103221↗