漏洞信息详情
PostgreSQL 访问控制错误漏洞
- CNNVD编号:CNNVD-201905-243
- 危害等级: 中危
- CVE编号: CVE-2019-10130
- 漏洞类型: 访问控制错误
- 发布时间: 2019-05-09
- 威胁类型: 远程
- 更新时间: 2021-01-19
- 厂 商:
- 漏洞来源: Ubuntu,Debian,Red ...
漏洞简介
PostgreSQL是PostgreSQL组织的一套自由的对象关系型数据库管理系统。该系统支持大部分SQL标准并且提供了许多其他特性,例如外键、触发器、视图等。
PostgreSQL中存在访问控制错误漏洞。攻击者可利用该漏洞绕过安全策略,获取信息。以下产品及版本受到影响:PostgreSQL 11.x版本至11.3版本,10.x版本至10.8版本,9.6.x版本至9.6.13版本,9.5.x版本至9.5.17版本。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.postgresql.org/about/news/1939/
参考网址
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.HTML
来源:CONFIRM
链接:https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10130
来源:GENTOO
链接:https://security.gentoo.org/glsa/202003-03
来源:MISC
链接:https://www.postgresql.org/about/news/1939/
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2019-10130
来源:bugzilla.redhat.com
链接:https://bugzilla.redhat.com/show_bug.cgi?id=1707109
来源:www.postgresql.org
链接:http://www.postgresql.org/
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191687-1.HTML
来源:www.debian.org
链接:http://www.debian.org/security/2019/dsa-4439
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191511-1.HTML
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192012-1.HTML
来源:www.postgresql.org
链接:https://www.postgresql.org/about/news/1939/
来源:usn.ubuntu.com
链接:https://usn.ubuntu.com/3972-1/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160982/Red-Hat-Security-Advisory-2021-0164-01.HTML
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/80718
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160592/Red-Hat-Security-Advisory-2020-5619-01.HTML
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/80606
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2128/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159665/Red-Hat-Security-Advisory-2020-4295-01.HTML
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0216/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4533/
来源:www.securityfocus.com
链接:https://www.securityfocus.com/bid/108452
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3074/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4469/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160665/Red-Hat-Security-Advisory-2020-5661-01.HTML
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/80770
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.2280/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-postgresql-vulnerabilities-in-ibm-robotic-process-automation-with-automation-anywhere/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/152780/Debian-Security-Advisory-4439-1.HTML
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/152824/Ubuntu-Security-Notice-USN-3972-1.HTML
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-10130
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3630/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156711/Gentoo-Linux-Security-Advisory-202003-03.HTML
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159089/Red-Hat-Security-Advisory-2020-3669-01.HTML
受影响实体
暂无
补丁
- PostgreSQL 安全漏洞的修复措施
![weinxin](http://zone.ci/zone_ci_images/zone.ci.png)
评论