CVE-2019-9193

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-9193
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-9193.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-9193
Withdrawn
2023-04-06T00:00:00Z
Published
2019-04-01T21:30:45Z
Modified
2024-11-21T04:51:10Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pgexecuteserver_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.

References

Affected packages

Git / git.postgresql.org/git/postgresql.git

Affected ranges

Type
GIT
Repo
https://git.postgresql.org/git/postgresql.git
Events
Introduced
da645b3a73580ac30cf02e932b42d06157b98229
Last affected
6cd404b344f7e27f4d64555bb133f18a758fe851