SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-3433

The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user…

MEDIUM 6.0EPSS 3.33%

Does this matter?

Lower severity and a low EPSS score (3.33%). Track it; it rarely justifies an emergency change on its own.

Description

The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.

CVSS 2.0
6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
EPSS
3.33% probability · 88th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
postgresql/postgresql
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.