CVE-2010-3433
Last modified
CVE-2010-3433 is a vulnerability of currently unknown severity. The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.. EPSS estimates a 3.33% chance of exploitation in the next 30 days.
Description
The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Postgresql | Postgresql | 7.4 |
| Postgresql | Postgresql | 7.4.1 |
| Postgresql | Postgresql | 7.4.2 |
| Postgresql | Postgresql | 7.4.3 |
| Postgresql | Postgresql | 7.4.4 |
| Postgresql | Postgresql | 7.4.5 |
| Postgresql | Postgresql | 7.4.6 |
| Postgresql | Postgresql | 7.4.7 |
| Postgresql | Postgresql | 7.4.8 |
| Postgresql | Postgresql | 7.4.9 |
| Postgresql | Postgresql | 7.4.10 |
| Postgresql | Postgresql | 7.4.11 |
| Postgresql | Postgresql | 7.4.12 |
| Postgresql | Postgresql | 7.4.13 |
| Postgresql | Postgresql | 7.4.14 |
| Postgresql | Postgresql | 7.4.15 |
| Postgresql | Postgresql | 7.4.16 |
| Postgresql | Postgresql | 7.4.17 |
| Postgresql | Postgresql | 7.4.18 |
| Postgresql | Postgresql | 7.4.19 |
| Postgresql | Postgresql | 7.4.20 |
| Postgresql | Postgresql | 7.4.21 |
| Postgresql | Postgresql | 7.4.22 |
| Postgresql | Postgresql | 7.4.23 |
| Postgresql | Postgresql | 7.4.24 |
| Postgresql | Postgresql | 7.4.25 |
| Postgresql | Postgresql | 7.4.26 |
| Postgresql | Postgresql | 7.4.27 |
| Postgresql | Postgresql | 7.4.28 |
| Postgresql | Postgresql | 7.4.29 |
| Postgresql | Postgresql | 8.0 |
| Postgresql | Postgresql | 8.0.1 |
| Postgresql | Postgresql | 8.0.2 |
| Postgresql | Postgresql | 8.0.3 |
| Postgresql | Postgresql | 8.0.4 |
| Postgresql | Postgresql | 8.0.5 |
| Postgresql | Postgresql | 8.0.6 |
| Postgresql | Postgresql | 8.0.7 |
| Postgresql | Postgresql | 8.0.8 |
| Postgresql | Postgresql | 8.0.9 |
| Postgresql | Postgresql | 8.0.10 |
| Postgresql | Postgresql | 8.0.11 |
| Postgresql | Postgresql | 8.0.12 |
| Postgresql | Postgresql | 8.0.13 |
| Postgresql | Postgresql | 8.0.14 |
| Postgresql | Postgresql | 8.0.15 |
| Postgresql | Postgresql | 8.0.16 |
| Postgresql | Postgresql | 8.0.17 |
| Postgresql | Postgresql | 8.0.18 |
| Postgresql | Postgresql | 8.0.19 |
Showing 50 of 114 affected configurations. See NVD for the full list.
References
- http://www.postgresql.org/about/news.1244Patch, Vendor Advisory
- http://www.postgresql.org/about/news.1244Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3433?
How severe is CVE-2010-3433?
How do I fix CVE-2010-3433?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-3427Multiple cross-site scripting (XSS) vulnerabilities in Open …
- CVE-2010-3428SQL injection vulnerability in modules/notes/json.php in Int…
- CVE-2010-3429flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used…
- CVE-2010-3430The privilege-dropping implementation in the (1) pam_env and…
- CVE-2010-3431The privilege-dropping implementation in the (1) pam_env and…
- CVE-2010-3432The sctp_packet_config function in net/sctp/output.c in the …
- CVE-2010-3434Buffer overflow in the find_stream_bounds function in pdf.c …
- CVE-2010-3435The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka p…
- CVE-2010-3436fopen_wrappers.c in PHP 5.3.x through 5.3.3 might allow remo…
- CVE-2010-3437Integer signedness error in the pkt_find_dev_from_minor func…
- CVE-2010-3438libpoe-component-irc-perl before v6.32 does not remove carri…9.8
- CVE-2010-3439It is possible to cause a DoS condition by causing the serve…6.5
Are you affected by CVE-2010-3433?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
