CVE-2019-9193
Summary
| CVE | CVE-2019-9193 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-01 21:30:00 UTC |
| Updated | 2023-11-07 03:13:00 UTC |
| Description | ** DISPUTED ** In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Postgresql | Postgresql | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Internet Archive: Scheduled Maintenance | MISC | packetstormsecurity.com | |
| Authenticated Arbitrary Command Execution on PostgreSQL 9.3 > Latest | Trustwave | MISC | www.trustwave.com | Third Party Advisory |
| Postgres 9.3 feature highlight - COPY TO/FROM PROGRAM | MISC | paquier.xyz | Third Party Advisory |
| When a vulnerability is not a vulnerability - Magnus Hagander's blog | MISC | blog.hagander.net | Third Party Advisory |
| PostgreSQL COPY FROM PROGRAM Command Execution ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory |
| Authenticated Arbitrary Command Execution on PostgreSQL 9.3 > Latest | MISC | medium.com | Exploit, Third Party Advisory |
| PostgreSQL 9.6.1 Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE-2019-9193 PostgreSQL in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.