CVE-2018-1058 Affecting postgresql-9.4 package, versions *


0.0
high

Snyk CVSS

    Attack Complexity Low
    Confidentiality High
    Integrity High
    Availability High

    Threat Intelligence

    EPSS 0.48% (76th percentile)
Expand this section
NVD
8.8 high
Expand this section
Red Hat
8.8 high

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-DEBIAN8-POSTGRESQL94-384931
  • published 2 Mar 2018
  • disclosed 2 Mar 2018

How to fix?

There is no fixed version for Debian:8 postgresql-9.4.

NVD Description

Note: Versions mentioned in the description apply only to the upstream postgresql-9.4 package and not the postgresql-9.4 package as distributed by Debian. See How to fix? for Debian:8 relevant fixed versions and status.

A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.