QID 375772
Date Published: 2021-08-19
QID 375772: PostgreSQL Have Multiple Vulnerabilities
PostgreSQL is a powerful, open source object-relational database system. It a strong reputation for reliability, feature robustness, and performance.
Affected Versions:
PostgreSQL versions before 13.4, before 12.8, before 11.13, before 10.18, before 9.6.23
QID Detection Logic(Auth):
This QID posts the version of PostgreSQL by checking file version of postgres.exe on windows and by sending psql version command on Linux.
Successful exploitation of these vulnerabilities affects the Confidentiality, Integrity and Availability
Solution
efer to Ubuntu advisory PostgreSQL 9.x PostgreSQL 10.xPostgreSQL 11.xPostgreSQL 12.xPostgreSQL 13.xfor affected versions.
Vendor References
- PostgreSQL 10.x -
www.postgresql.org/docs/release/10.18/ - PostgreSQL 11.x -
www.postgresql.org/docs/release/11.13/ - PostgreSQL 12.x -
www.postgresql.org/docs/release/12.8/ - PostgreSQL 13.x -
www.postgresql.org/docs/release/13.4/ - PostgreSQL 9.x -
www.postgresql.org/docs/release/9.6.23/
CVEs related to QID 375772
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PostgreSQL 10 |
|
||
| PostgreSQL 10 |
|
||
| PostgreSQL 13 |
|
||
| PostgreSQL11 |
|
||
| PostgreSQL12 |
|