CVE-2018-10925
Last modified
CVE-2018-10925 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". EPSS estimates a 2.24% chance of exploitation in the next 30 days.
Description
It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "CREATE TABLE" privileges could exploit this to read arbitrary bytes server memory. If the attacker also had certain "INSERT" and limited "UPDATE" privileges to a particular table, they could exploit this to update other columns in the same table.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Debian | Debian Linux | 9.0 |
| Postgresql | Postgresql | >= 9.5.0, < 9.5.14 |
| Postgresql | Postgresql | >= 9.6.0, < 9.6.10 |
| Postgresql | Postgresql | >= 10.0, < 10.5 |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/105052Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041446Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:2511Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2565Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2566Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3816Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10925Issue Tracking, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/201810-08Third Party Advisory
- https://usn.ubuntu.com/3744-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4269Third Party Advisory
- https://www.postgresql.org/about/news/1878/Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/105052Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041446Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:2511Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2565Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2566Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3816Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10925Issue Tracking, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/201810-08Third Party Advisory
- https://usn.ubuntu.com/3744-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4269Third Party Advisory
- https://www.postgresql.org/about/news/1878/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10925?
How severe is CVE-2018-10925?
How do I fix CVE-2018-10925?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1092The ext4_iget function in fs/ext4/inode.c in the Linux kerne…
- CVE-2018-10920Improper input validation bug in DNS resolver component of K…6.8
- CVE-2018-10921Certain input files may trigger an integer overflow in ttemb…4.3
- CVE-2018-10922An input validation flaw exists in ttembed. With a crafted i…7.5
- CVE-2018-10923It was found that the "mknod" call derived from mknod(2) can…8.1
- CVE-2018-10924It was discovered that fsync(2) system call in glusterfs cli…5.3
- CVE-2018-10926A flaw was found in RPC request using gfs3_mknod_req support…8.8
- CVE-2018-10927A flaw was found in RPC request using gfs3_lookup_req in glu…8.1
- CVE-2018-10928A flaw was found in RPC request using gfs3_symlink_req in gl…8.8
- CVE-2018-10929A flaw was found in RPC request using gfs2_create_req in glu…8.8
- CVE-2018-1093The ext4_valid_block_bitmap function in fs/ext4/balloc.c in …
- CVE-2018-10930A flaw was found in RPC request using gfs3_rename_req in glu…6.5
Are you affected by CVE-2018-10925?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
