vulnerability

SUSE: CVE-2019-10208: SUSE Linux Security Advisory

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
Aug 8, 2019
Added
Aug 22, 2019
Modified
Oct 22, 2021

Description

A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 where arbitrary SQL statements can be executed given a suitable SECURITY DEFINER function. An attacker, with EXECUTE permission on the function, can execute arbitrary SQL as the owner of the function.

Solution(s)

suse-upgrade-libecpg6suse-upgrade-libecpg6-32bitsuse-upgrade-libpq5suse-upgrade-libpq5-32bitsuse-upgrade-postgresqlsuse-upgrade-postgresql-contribsuse-upgrade-postgresql-develsuse-upgrade-postgresql-docssuse-upgrade-postgresql-llvmjitsuse-upgrade-postgresql-plperlsuse-upgrade-postgresql-plpythonsuse-upgrade-postgresql-pltclsuse-upgrade-postgresql-serversuse-upgrade-postgresql-server-develsuse-upgrade-postgresql-testsuse-upgrade-postgresql10suse-upgrade-postgresql10-contribsuse-upgrade-postgresql10-develsuse-upgrade-postgresql10-docssuse-upgrade-postgresql10-plperlsuse-upgrade-postgresql10-plpythonsuse-upgrade-postgresql10-pltclsuse-upgrade-postgresql10-serversuse-upgrade-postgresql10-testsuse-upgrade-postgresql12suse-upgrade-postgresql12-contribsuse-upgrade-postgresql12-develsuse-upgrade-postgresql12-docssuse-upgrade-postgresql12-llvmjitsuse-upgrade-postgresql12-plperlsuse-upgrade-postgresql12-plpythonsuse-upgrade-postgresql12-pltclsuse-upgrade-postgresql12-serversuse-upgrade-postgresql12-server-develsuse-upgrade-postgresql12-testsuse-upgrade-postgresql94suse-upgrade-postgresql94-contribsuse-upgrade-postgresql94-docssuse-upgrade-postgresql94-plperlsuse-upgrade-postgresql94-plpythonsuse-upgrade-postgresql94-pltclsuse-upgrade-postgresql94-serversuse-upgrade-postgresql96suse-upgrade-postgresql96-contribsuse-upgrade-postgresql96-develsuse-upgrade-postgresql96-docssuse-upgrade-postgresql96-plperlsuse-upgrade-postgresql96-plpythonsuse-upgrade-postgresql96-pltclsuse-upgrade-postgresql96-serversuse-upgrade-postgresql96-test
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.