CVE-2019-10208
Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function call having inexact argument type match. For example, length('foo'::varchar) and length('foo') are inexact, while length('foo'::text) is exact.
As part of exploiting this vulnerability, the attacker uses CREATE DOMAIN to create a type in a pg_temp schema. The attack pattern and fix are similar to that for CVE-2007-2138 .
Writing SECURITY DEFINER functions continues to require following the considerations noted in the documentation:
https://www.postgresql.org/docs/current/sql-createfunction.html#SQL-CREATEFUNCTION-SECURITY
The PostgreSQL project thanks Tom Lane for reporting this problem.
Version Information
| Affected branch | Introduced | Fixed In | Fix Published |
|---|
| 10 | — | 10.10 | 2019-08-08 |
| 11 | — | 11.5 | 2019-08-08 |
| 9.4 | — | 9.4.24 | 2019-08-08 |
| 9.5 | — | 9.5.19 | 2019-08-08 |
| 9.6 | — | 9.6.15 | 2019-08-08 |
CVSS 3.0
| Overall Score | 7.5 |
|---|
| Component | core server |
|---|
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
|---|
First published: 2019-08-08
Original security advisory · JSON · All advisories