SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-10915

A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections.

HIGH 7.5EPSS 5.15%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (5.15%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could bypass client-side connection security features, obtain access to higher privileged connections or potentially cause other impact through SQL injection, by causing the PQescape() functions to malfunction. Postgresql versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 are affected.

CVSS 3.0
7.5 HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
5.15% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-89, CWE-200, CWE-665
Affected
redhat/openstack · redhat/virtualization · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server eus · redhat/enterprise linux workstation · canonical/ubuntu linux · debian/debian linux · postgresql/postgresql
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.