SB2018110830 - SQL injection in postgresql (Alpine package)
Published: November 8, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) SQL injection (CVE-ID: CVE-2018-16850)
The vulnerability allows a remote authenticated attacker to execute arbitrary SQL commands in web application database.
The vulnerability exists due to insufficient sanitization of statements involving CREATE TRIGGER REFERENCING. A remote attacker can send a specially crafted HTTP request to vulnerable script and execute arbitrary SQL commands in web application database when running the pg_upgrade utility on the database or during a pg_dump utility dump/restore cycle.
Successful exploitation of the vulnerability may allow an attacker to gain administrative access to vulnerable web application.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=5600c80ab97b0bed725ec1c24f981a765e54593b
- https://git.alpinelinux.org/aports/commit/?id=2b95c8929982c3ff86b48ffe921cf9ddff6aeebd
- https://git.alpinelinux.org/aports/commit/?id=5f580c412de14f7329bf77293a1c8bbce8a74d48
- https://git.alpinelinux.org/aports/commit/?id=3c20033f75ab5c8b506ad5e4acb3438626aff953
- https://git.alpinelinux.org/aports/commit/?id=7cf139bac41c8f2e1885d5f99334daeaeb059ac3
- https://git.alpinelinux.org/aports/commit/?id=aea07a63d90d0cde39022c14973acfc56ff8d6f2