Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
PostgreSQL versions 9.3 through 11.7 remote code execution exploit (packetstormsecurity.com)
4 points by Bender on March 31, 2022 | hide | past | favorite | 4 comments


https://www.postgresql.org/about/news/cve-2019-9193-not-a-se...

> There is widespread mention in the media of a security vulnerability in PostgreSQL, registered as CVE-2019-9193. The PostgreSQL Security Team would like to emphasize that this is not a security vulnerability. We believe the CVE entry was filed in error. We have contacted the reporter to investigate the issue.


For what it's worth, the PoC code is on that URL allowing one to test the script against their servers. I do not currently have that range of versions installed anywhere to test against. Im on 14


And I'm too scared to try against mine


it works if you are superuser. else it wont. also who allows users to run untrusted sql.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: