{"id":"CVE-2019-10208","year":2019,"sequence":10208,"component":"core server","score":7.5,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","first_published":"2019-08-08","source_url":"https://www.postgresql.org/support/security/CVE-2019-10208/","facts":{"affected":{"10":"10","11":"11","9.4":"9.4","9.5":"9.5","9.6":"9.6"},"component":"core server","cvss_version":"3.0","description_en":"Given a suitable SECURITY DEFINER function, an attacker can execute arbitrary SQL under the identity of the function owner. An attack requires EXECUTE permission on the function, which must itself contain a function call having inexact argument type match. For example, length('foo'::varchar) and length('foo') are inexact, while length('foo'::text) is exact.\n\nAs part of exploiting this vulnerability, the attacker uses CREATE DOMAIN to create a type in a pg_temp schema. The attack pattern and fix are similar to that for CVE-2007-2138 .\n\nWriting SECURITY DEFINER functions continues to require following the considerations noted in the documentation:\n\nhttps://www.postgresql.org/docs/current/sql-createfunction.html#SQL-CREATEFUNCTION-SECURITY\n\nThe PostgreSQL project thanks Tom Lane for reporting this problem.","first_published":"2019-08-08","fixed":{"10":"10.10","11":"11.5","9.4":"9.4.24","9.5":"9.5.19","9.6":"9.6.15"},"id":"CVE-2019-10208","introduced":{},"published":{"10":"2019-08-08","11":"2019-08-08","9.4":"2019-08-08","9.5":"2019-08-08","9.6":"2019-08-08"},"score":7.5,"title":"TYPE in pg_temp executes arbitrary SQL during SECURITY DEFINER execution","url":"https://www.postgresql.org/support/security/CVE-2019-10208/","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":null,"locales":["en"],"fixes":[{"major":"10","fixed_version":"10.10","introduced":null,"published_date":"2019-08-08","facts":{"fixed":"10.10","introduced":null,"published":"2019-08-08"}},{"major":"11","fixed_version":"11.5","introduced":null,"published_date":"2019-08-08","facts":{"fixed":"11.5","introduced":null,"published":"2019-08-08"}},{"major":"9.4","fixed_version":"9.4.24","introduced":null,"published_date":"2019-08-08","facts":{"fixed":"9.4.24","introduced":null,"published":"2019-08-08"}},{"major":"9.5","fixed_version":"9.5.19","introduced":null,"published_date":"2019-08-08","facts":{"fixed":"9.5.19","introduced":null,"published":"2019-08-08"}},{"major":"9.6","fixed_version":"9.6.15","introduced":null,"published_date":"2019-08-08","facts":{"fixed":"9.6.15","introduced":null,"published":"2019-08-08"}}],"legacy":[]}
