All errata/p9/ALT-PU-2020-2011-1
ALT-PU-2020-2011-1

Package update postgresql9.6 in branch p9

Version9.6.18-alt1
Published2020-05-25
Max severityHIGH
Severity:

Closed issues (2)

BDU:2023-00612
MEDIUM6.7

Уязвимость установщика Windows installer системы управления базами данных PostgreSQL, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

Published: 2023-02-08
CVSS 3.xMEDIUM 6.7
CVSS:3.x/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS 2.0MEDIUM 6.0
CVSS:2.0/AV:L/AC:H/Au:S/C:C/I:C/A:C
References
CVE-2020-10733
HIGH7.3

The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights.

Published: 2020-09-16Modified: 2024-11-21
CVSS 2.0MEDIUM 4.4
CVSS:2.0/AV:L/AC:M/Au:N/C:P/I:P/A:P
CVSS 3.xHIGH 7.3
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H