Wind River Support Network

HomeDefectsLIN1018-6585
Fixed

LIN1018-6585 : Security Advisory - postgresql - CVE-2020-14349

Created: Aug 19, 2020    Updated: Dec 7, 2020
Resolved Date: Sep 6, 2020
Found In Version: 10.18.44.1
Fix Version: 10.18.44.19
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.

https://nvd.nist.gov/vuln/detail/CVE-2020-14349

CVEs


Live chat
Online