CVE-2018-1058
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 13%
probabilidad de explotación
13%top 4% de las CVE
explotación observada
noninguna fuente lo reporta
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.
Productos afectados
The PostgreSQL Global Development Group · postgresqlReferencias
https://access.redhat.com/errata/RHSA-2018:2511https://access.redhat.com/errata/RHSA-2018:2566https://access.redhat.com/errata/RHSA-2018:3816https://bugzilla.redhat.com/show_bug.cgi?id=1547044https://usn.ubuntu.com/3589-1/https://www.postgresql.org/about/news/1834/http://www.securityfocus.com/bid/103221