8.5
CVSSv2

CVE-2010-1169

Published: 19/05/2010 Updated: 19/09/2017
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
VMScore: 758
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

PostgreSQL 7.4 prior to 7.4.29, 8.0 prior to 8.0.25, 8.1 prior to 8.1.21, 8.2 prior to 8.2.17, 8.3 prior to 8.3.11, 8.4 prior to 8.4.4, and 9.0 Beta prior to 9.0 Beta 2 does not properly restrict PL/perl procedures, which allows remote authenticated users, with database-creation privileges, to execute arbitrary Perl code via a crafted script, related to the Safe module (aka Safe.pm) for Perl. NOTE: some sources report that this issue is the same as CVE-2010-1447.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql 7.4.5

postgresql postgresql 7.4.4

postgresql postgresql 7.4

postgresql postgresql 7.4.1

postgresql postgresql 7.4.14

postgresql postgresql 7.4.15

postgresql postgresql 7.4.28

postgresql postgresql 7.4.27

postgresql postgresql 7.4.3

postgresql postgresql 7.4.2

postgresql postgresql 7.4.8

postgresql postgresql 7.4.18

postgresql postgresql 7.4.25

postgresql postgresql 7.4.13

postgresql postgresql 7.4.21

postgresql postgresql 7.4.26

postgresql postgresql 7.4.7

postgresql postgresql 7.4.24

postgresql postgresql 7.4.10

postgresql postgresql 7.4.22

postgresql postgresql 7.4.19

postgresql postgresql 7.4.16

postgresql postgresql 7.4.6

postgresql postgresql 7.4.9

postgresql postgresql 7.4.11

postgresql postgresql 7.4.23

postgresql postgresql 7.4.12

postgresql postgresql 7.4.20

postgresql postgresql 7.4.17

postgresql postgresql 8.0.1

postgresql postgresql 8.0.14

postgresql postgresql 8.0.18

postgresql postgresql 8.0.19

postgresql postgresql 8.0.6

postgresql postgresql 8.0.22

postgresql postgresql 8.0

postgresql postgresql 8.0.10

postgresql postgresql 8.0.16

postgresql postgresql 8.0.17

postgresql postgresql 8.0.8

postgresql postgresql 8.0.5

postgresql postgresql 8.0.11

postgresql postgresql 8.0.2

postgresql postgresql 8.0.23

postgresql postgresql 8.0.13

postgresql postgresql 8.0.12

postgresql postgresql 8.0.15

postgresql postgresql 8.0.9

postgresql postgresql 8.0.24

postgresql postgresql 8.0.20

postgresql postgresql 8.0.0

postgresql postgresql 8.0.4

postgresql postgresql 8.0.3

postgresql postgresql 8.0.21

postgresql postgresql 8.0.7

postgresql postgresql 8.1.2

postgresql postgresql 8.1.5

postgresql postgresql 8.1.4

postgresql postgresql 8.1.18

postgresql postgresql 8.1.15

postgresql postgresql 8.1.7

postgresql postgresql 8.1.8

postgresql postgresql 8.1.6

postgresql postgresql 8.1.3

postgresql postgresql 8.1.0

postgresql postgresql 8.1.17

postgresql postgresql 8.1.11

postgresql postgresql 8.1.16

postgresql postgresql 8.1

postgresql postgresql 8.1.19

postgresql postgresql 8.1.14

postgresql postgresql 8.1.12

postgresql postgresql 8.1.9

postgresql postgresql 8.1.1

postgresql postgresql 8.1.20

postgresql postgresql 8.1.10

postgresql postgresql 8.1.13

postgresql postgresql 8.2.5

postgresql postgresql 8.2.9

postgresql postgresql 8.2.14

postgresql postgresql 8.2

postgresql postgresql 8.2.7

postgresql postgresql 8.2.6

postgresql postgresql 8.2.11

postgresql postgresql 8.2.16

postgresql postgresql 8.2.15

postgresql postgresql 8.2.12

postgresql postgresql 8.2.8

postgresql postgresql 8.2.13

postgresql postgresql 8.2.1

postgresql postgresql 8.2.3

postgresql postgresql 8.2.2

postgresql postgresql 8.2.10

postgresql postgresql 8.2.4

postgresql postgresql 8.3.1

postgresql postgresql 8.3.4

postgresql postgresql 8.3.5

postgresql postgresql 8.3.2

postgresql postgresql 8.3.8

postgresql postgresql 8.3.3

postgresql postgresql 8.3

postgresql postgresql 8.3.7

postgresql postgresql 8.3.6

postgresql postgresql 8.3.10

postgresql postgresql 8.3.9

postgresql postgresql 8.4

postgresql postgresql 8.4.2

postgresql postgresql 8.4.1

postgresql postgresql 8.4.3

postgresql postgresql 9.0.0

Vendor Advisories

Debian Bug report logs - #582978 perl: safepm code injection vulnerability Package: perl; Maintainer for perl is Niko Tyni <ntyni@debianorg>; Source for perl is src:perl (PTS, buildd, popcon) Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Tue, 25 May 2010 04:39:02 UTC Severity: serious Tags: secu ...
If PostgreSQL was configured to use Perl and/or Tcl stored procedures a remote authenticated attacker could run programs as the database user ...

References

CWE-94http://www.securityfocus.com/bid/40215http://www.postgresql.org/docs/current/static/release-8-4-4.htmlhttp://www.postgresql.org/docs/current/static/release-8-3-11.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=582615http://www.postgresql.org/support/securityhttp://www.postgresql.org/docs/current/static/release-8-0-25.htmlhttp://secunia.com/advisories/39845http://www.postgresql.org/docs/current/static/release-8-2-17.htmlhttp://www.postgresql.org/docs/current/static/release-7-4-29.htmlhttp://www.vupen.com/english/advisories/2010/1167http://www.postgresql.org/docs/current/static/release-8-1-21.htmlhttp://www.postgresql.org/about/news.1203http://www.redhat.com/support/errata/RHSA-2010-0427.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0430.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0429.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0428.htmlhttp://www.securitytracker.com/id?1023988http://www.mandriva.com/security/advisories?name=MDVSA-2010:103http://www.vupen.com/english/advisories/2010/1207http://secunia.com/advisories/39898http://secunia.com/advisories/39820http://www.vupen.com/english/advisories/2010/1198http://www.vupen.com/english/advisories/2010/1197http://www.debian.org/security/2010/dsa-2051http://secunia.com/advisories/39939http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041579.htmlhttp://www.vupen.com/english/advisories/2010/1221http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041591.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-May/041559.htmlhttp://secunia.com/advisories/39815http://www.vupen.com/english/advisories/2010/1182http://www.openwall.com/lists/oss-security/2010/05/20/5https://bugzilla.redhat.com/show_bug.cgi?id=588269http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://osvdb.org/64755http://marc.info/?l=bugtraq&m=134124585221119&w=2https://exchange.xforce.ibmcloud.com/vulnerabilities/58693https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10645https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=582978https://usn.ubuntu.com/942-1/https://nvd.nist.gov