CVE-2018-10915
Summary
| CVE | CVE-2018-10915 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-09 20:29:00 UTC |
| Updated | 2021-08-04 17:14:00 UTC |
| Description | A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could bypass client-side connection security features, obtain access to higher privileged connections or potentially cause other impact through SQL injection, by causing the PQescape() functions to malfunction. Postgresql versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 are affected. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| 1609891 – (CVE-2018-10915) CVE-2018-10915 postgresql: Certain host connection parameters defeat client-side security defenses |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| PostgreSQL CVE-2018-10915 Security Bypass Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| [SECURITY] [DLA 1464-1] postgresql-9.4 security update |
MLIST |
lists.debian.org |
Third Party Advisory |
| PostgreSQL: Multiple vulnerabilities (GLSA 201810-08) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| USN-3744-1: PostgreSQL vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| PostgreSQL: PostgreSQL 10.5, 9.6.10, 9.5.14, 9.4.19, 9.3.24, and 11 Beta 3 Released! |
CONFIRM |
www.postgresql.org |
Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| [security-announce] openSUSE-SU-2020:1227-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| PostgreSQL Bugs Let Remote Authenticated Users Access Systems and Obtain Potentially Sensitive Information from System Memory - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Debian -- Security Information -- DSA-4269-1 postgresql-9.6 |
DEBIAN |
www.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500533 Alpine Linux Security Update for postgresql
- 502001 Alpine Linux Security Update for postgresql14
- 502767 Alpine Linux Security Update for postgresql15
- 504300 Alpine Linux Security Update for postgresql14
- 710227 Gentoo Linux PostgreSQL Multiple Vulnerabilities (GLSA 201810-08)