CVE-2023-39417
Summary
| CVE | CVE-2023-39417 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-11 13:15:00 UTC |
| Updated | 2024-01-25 09:15:00 UTC |
| Description | IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161207 Oracle Enterprise Linux Security Update for postgresql:13 (ELSA-2023-7581)
- 161232 Oracle Enterprise Linux Security Update for postgresql:15 (ELSA-2023-7785)
- 161242 Oracle Enterprise Linux Security Update for postgresql (ELSA-2023-7784)
- 161250 Oracle Enterprise Linux Security Update for postgresql:12 (ELSA-2023-7714)
- 161253 Oracle Enterprise Linux Security Update for postgresql:15 (ELSA-2023-7884)
- 199665 Ubuntu Security Notification for PostgreSQL Vulnerabilities (USN-6296-1)
- 242527 Red Hat Update for postgresql (RHSA-2023:7545)
- 242534 Red Hat Update for postgresql:13 (RHSA-2023:7580)
- 242536 Red Hat Update for postgresql:13 (RHSA-2023:7581)
- 242537 Red Hat Update for postgresql:13 (RHSA-2023:7579)
- 242540 Red Hat Update for postgresql (RHSA-2023:7616)
- 242544 Red Hat Update for postgresql:12 (RHSA-2023:7656)
- 242546 Red Hat Update for postgresql:12 (RHSA-2023:7666)
- 242547 Red Hat Update for postgresql:12 (RHSA-2023:7667)
- 242550 Red Hat Update for postgresql:13 (RHSA-2023:7695)
- 242552 Red Hat Update for postgresql:12 (RHSA-2023:7694)
- 242558 Red Hat Update for postgresql:12 (RHSA-2023:7714)
- 242591 Red Hat Update for rh-postgresql12-postgresql (RHSA-2023:7770)
- 242592 Red Hat Update for rh-postgresql13-postgresql (RHSA-2023:7772)
- 242611 Red Hat Update for postgresql (RHSA-2023:7784)
- 242614 Red Hat Update for postgresql:15 (RHSA-2023:7785)
- 242634 Red Hat Update for postgresql:15 (RHSA-2023:7885)
- 242636 Red Hat Update for postgresql:15 (RHSA-2023:7883)
- 242657 Red Hat Update for postgresql:15 (RHSA-2023:7884)
- 356204 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL14-2023-003
- 356250 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL11-2023-004
- 356257 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL12-2023-005
- 356308 Amazon Linux Security Advisory for postgresql : ALASPOSTGRESQL13-2023-004
- 356473 Amazon Linux Security Advisory for postgresql : ALAS2POSTGRESQL12-2023-005
- 356492 Amazon Linux Security Advisory for postgresql : ALAS2POSTGRESQL11-2023-004
- 379115 Alibaba Cloud Linux Security Update for postgresql:13 (ALINUX3-SA-2023:0139)
- 379588 Gitlab Multiple Vulnerabilities (prior to gitlab- 16.6.1, 16.5.3, 16.4.3)
- 503280 Alpine Linux Security Update for postgresql
- 503281 Alpine Linux Security Update for postgresql13
- 503282 Alpine Linux Security Update for postgresql14
- 503283 Alpine Linux Security Update for postgresql12
- 503284 Alpine Linux Security Update for postgresql15
- 505920 Alpine Linux Security Update for postgresql15
- 506163 Alpine Linux Security Update for postgresql13
- 506165 Alpine Linux Security Update for postgresql14
- 6000141 Debian Security Update for postgresql-11 (DLA 3600-1)
- 6000321 Debian Security Update for postgresql-13 (DSA 5554-1)
- 6000322 Debian Security Update for postgresql-15 (DSA 5553-1)
- 673920 EulerOS Security Update for postgresql (EulerOS-SA-2023-3146)
- 691228 Free Berkeley Software Distribution (FreeBSD) Security Update for postgresql (cfd2a634-3785-11ee-94b4-6cc21735f730)
- 754277 SUSE Enterprise Linux Security Update for postgresql15 (SUSE-SU-2023:3343-1)
- 754278 SUSE Enterprise Linux Security Update for postgresql15 (SUSE-SU-2023:3342-1)
- 754279 SUSE Enterprise Linux Security Update for postgresql12 (SUSE-SU-2023:3341-1)
- 754282 SUSE Enterprise Linux Security Update for postgresql12 (SUSE-SU-2023:3346-1)
- 754283 SUSE Enterprise Linux Security Update for postgresql15 (SUSE-SU-2023:3345-1)
- 907731 Common Base Linux Mariner (CBL-Mariner) Security Update for postgresql (27892-1)
- 941485 AlmaLinux Security Update for postgresql:13 (ALSA-2023:7581)
- 941501 AlmaLinux Security Update for postgresql (ALSA-2023:7784)
- 941508 AlmaLinux Security Update for postgresql:12 (ALSA-2023:7714)
- 941510 AlmaLinux Security Update for postgresql:15 (ALSA-2023:7785)
- 941512 AlmaLinux Security Update for postgresql:15 (ALSA-2023:7884)
- 961088 Rocky Linux Security Update for postgresql:13 (RLSA-2023:7581)