CVE-2023-39417

IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.
References
Link Resource
https://access.redhat.com/errata/RHSA-2023:7545 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7579 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7580 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7581 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7616 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7656 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7666 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7667 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7694 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7695 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7714 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7770 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7772 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7784 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7785 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7883 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7884 Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:7885 Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0304 Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0332 Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0337 Third Party Advisory
https://access.redhat.com/security/cve/CVE-2023-39417 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2228111 Issue Tracking Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/10/msg00003.html Mailing List
https://security.netapp.com/advisory/ntap-20230915-0002/ Third Party Advisory
https://www.debian.org/security/2023/dsa-5553 Third Party Advisory
https://www.debian.org/security/2023/dsa-5554 Third Party Advisory
https://www.postgresql.org/support/security/CVE-2023-39417 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:software_collections:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-08-11 13:15

Updated : 2024-02-16 15:20


NVD link : CVE-2023-39417

Mitre link : CVE-2023-39417

CVE.ORG link : CVE-2023-39417


JSON object : View

Products Affected

debian

  • debian_linux

postgresql

  • postgresql

redhat

  • enterprise_linux
  • software_collections
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')