Description
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
4.2.4-6 (rpm) before *
4.2.4-6 (rpm) before *
4.2.4-7 (rpm) before *
4.2.4-6 (rpm) before *
4.2.4-7 (rpm) before *
8090020231114113712.a75119d5 (rpm) before *
8090020231128173330.a75119d5 (rpm) before *
8090020231114113548.a75119d5 (rpm) before *
8020020231128165246.4cda2c84 (rpm) before *
8020020231128165246.4cda2c84 (rpm) before *
8020020231128165246.4cda2c84 (rpm) before *
8040020231127153301.522a0ee4 (rpm) before *
8040020231127154806.522a0ee4 (rpm) before *
8040020231127153301.522a0ee4 (rpm) before *
8040020231127154806.522a0ee4 (rpm) before *
8040020231127153301.522a0ee4 (rpm) before *
8040020231127154806.522a0ee4 (rpm) before *
8060020231114115246.ad008a3a (rpm) before *
8060020231128165328.ad008a3a (rpm) before *
8080020231114105206.63b34585 (rpm) before *
8080020231128165335.63b34585 (rpm) before *
8080020231113134015.63b34585 (rpm) before *
0:13.13-1.el9_3 (rpm) before *
9030020231120082734.rhel9 (rpm) before *
0:13.13-1.el9_0 (rpm) before *
0:13.13-1.el9_2 (rpm) before *
9020020231115020618.rhel9 (rpm) before *
0:12.17-1.el7 (rpm) before *
0:13.13-1.el7 (rpm) before *
3.74.8-9 (rpm) before *
3.74.8-9 (rpm) before *
3.74.8-7 (rpm) before *
3.74.8-9 (rpm) before *
3.74.8-9 (rpm) before *
4.1.6-6 (rpm) before *
4.1.6-6 (rpm) before *
4.1.6-6 (rpm) before *
4.1.6-6 (rpm) before *
4.1.6-6 (rpm) before *
Timeline
| 2023-08-01: | Reported to Red Hat. |
| 2023-08-10: | Made public. |
References
access.redhat.com/errata/RHSA-2023:7545 (RHSA-2023:7545)
access.redhat.com/errata/RHSA-2023:7579 (RHSA-2023:7579)
access.redhat.com/errata/RHSA-2023:7580 (RHSA-2023:7580)
access.redhat.com/errata/RHSA-2023:7581 (RHSA-2023:7581)
access.redhat.com/errata/RHSA-2023:7616 (RHSA-2023:7616)
access.redhat.com/errata/RHSA-2023:7656 (RHSA-2023:7656)
access.redhat.com/errata/RHSA-2023:7666 (RHSA-2023:7666)
access.redhat.com/errata/RHSA-2023:7667 (RHSA-2023:7667)
access.redhat.com/errata/RHSA-2023:7694 (RHSA-2023:7694)
access.redhat.com/errata/RHSA-2023:7695 (RHSA-2023:7695)
access.redhat.com/errata/RHSA-2023:7714 (RHSA-2023:7714)
access.redhat.com/errata/RHSA-2023:7770 (RHSA-2023:7770)
access.redhat.com/errata/RHSA-2023:7772 (RHSA-2023:7772)
access.redhat.com/errata/RHSA-2023:7784 (RHSA-2023:7784)
access.redhat.com/errata/RHSA-2023:7785 (RHSA-2023:7785)
access.redhat.com/errata/RHSA-2023:7883 (RHSA-2023:7883)
access.redhat.com/errata/RHSA-2023:7884 (RHSA-2023:7884)
access.redhat.com/errata/RHSA-2023:7885 (RHSA-2023:7885)
access.redhat.com/errata/RHSA-2024:0304 (RHSA-2024:0304)
access.redhat.com/errata/RHSA-2024:0332 (RHSA-2024:0332)
access.redhat.com/errata/RHSA-2024:0337 (RHSA-2024:0337)
access.redhat.com/security/cve/CVE-2023-39417
bugzilla.redhat.com/show_bug.cgi?id=2228111 (RHBZ#2228111)
lists.debian.org/debian-lts-announce/2023/10/msg00003.html
security.netapp.com/advisory/ntap-20230915-0002/
www.debian.org/security/2023/dsa-5553
www.debian.org/security/2023/dsa-5554
www.postgresql.org/support/security/CVE-2023-39417
access.redhat.com/errata/RHSA-2023:7545 (RHSA-2023:7545)
access.redhat.com/errata/RHSA-2023:7579 (RHSA-2023:7579)
access.redhat.com/errata/RHSA-2023:7580 (RHSA-2023:7580)
access.redhat.com/errata/RHSA-2023:7581 (RHSA-2023:7581)
access.redhat.com/errata/RHSA-2023:7616 (RHSA-2023:7616)
access.redhat.com/errata/RHSA-2023:7656 (RHSA-2023:7656)
access.redhat.com/errata/RHSA-2023:7666 (RHSA-2023:7666)
access.redhat.com/errata/RHSA-2023:7667 (RHSA-2023:7667)
access.redhat.com/errata/RHSA-2023:7694 (RHSA-2023:7694)
access.redhat.com/errata/RHSA-2023:7695 (RHSA-2023:7695)
access.redhat.com/errata/RHSA-2023:7714 (RHSA-2023:7714)
access.redhat.com/errata/RHSA-2023:7770 (RHSA-2023:7770)
access.redhat.com/errata/RHSA-2023:7772 (RHSA-2023:7772)
access.redhat.com/errata/RHSA-2023:7784 (RHSA-2023:7784)
access.redhat.com/errata/RHSA-2023:7785 (RHSA-2023:7785)
access.redhat.com/errata/RHSA-2023:7883 (RHSA-2023:7883)
access.redhat.com/errata/RHSA-2023:7884 (RHSA-2023:7884)
access.redhat.com/errata/RHSA-2023:7885 (RHSA-2023:7885)
access.redhat.com/errata/RHSA-2024:0304 (RHSA-2024:0304)
access.redhat.com/errata/RHSA-2024:0332 (RHSA-2024:0332)
access.redhat.com/errata/RHSA-2024:0337 (RHSA-2024:0337)
access.redhat.com/security/cve/CVE-2023-39417
bugzilla.redhat.com/show_bug.cgi?id=2228111 (RHBZ#2228111)
www.postgresql.org/support/security/CVE-2023-39417