↑↓ select↵ open⌫ change scopeOpen full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

CVE-2019-10208

Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function call having inexact argument type match. For example, length('foo'::varchar) and length('foo') are inexact, while length('foo'::text) is exact. As part of exploiting this vulnerability, the attacker uses CREATE DOMAIN to create a type in a pg_temp schema. The attack pattern and fix are similar to that for CVE-2007-2138 . Writing SECURITY DEFINER functions continues to require following the considerations noted in the documentation: https://www.postgresql.org/docs/current/sql-createfunction.html#SQL-CREATEFUNCTION-SECURITY The PostgreSQL project thanks Tom Lane for reporting this problem.

Version Information

Affected branchIntroducedFixed InFix Published
10—10.102019-08-08
11—11.52019-08-08
9.4—9.4.242019-08-08
9.5—9.5.192019-08-08
9.6—9.6.152019-08-08

CVSS 3.0

Overall Score7.5
Componentcore server
VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

First published: 2019-08-08

Original security advisory · JSON · All advisories