PostgreSQLËÁÒâ´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-03-27

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-9193£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


ÊÜÓ°Ïì°æ±¾£º 

PostgreSQL >=9.3


·ì϶¸ÅÊö


½üÈÕ£¬°²È«×êÑÐÈËÔ±Åû¶ÁËPostgreSQLÌáȨ´úÂëÖ´Ðзì϶µÄ·ì϶ϸ½Ú£¬¾ßº±¼û¾Ý¿â·þÎñ¶ËÎļþ¶ÁȨÏ޵Ĺ¥»÷ÕßÀûÓô˷ì϶£¬¿ÉÖ´ÐÐËÁÒâϵͳºÅÁî¡£

PostgreSQLÊÇÒ»¿îÖ°ÄÜ׳´óµÄÊý¾Ý¿âÈí¼þ£¬¿ÉÔËÐÐÔÚËùÓÐÖ÷Á÷²Ù×÷ϵͳÉÏ£¬Ô̺¬Linux¡¢Windows¡¢Mac OS XµÈ¡£Õâ´ÎÅû¶µÄ·ì϶´æÔÚÓÚµ¼Èëµ¼³öÊý¾ÝµÄºÅÁî¡°COPY TO/FROM PROGRAM¡±ÖУ¬¡°pg_read_server_files¡±×éÄÚÓû§Ö´ÐÐÉÏÊöºÅÁîºó£¬¿É»ñÈ¡Êý¾Ý¿â³¬µÈÓû§È¨ÏÞ£¬´Ó¶øÖ´ÐÐËÁÒâϵͳºÅÁî¡£


½¨¸´½¨Òé


Ŀǰ¹Ù·½½¨¸´´Ë·ì϶µÄ´òËã¡£pg_read_server_files¡¢pg_write_server_files¡¢pg_execute_server_program ½Çɫɿ¼°µ½¶ÁдÊý¾Ý¿â·þÎñ¶ËÎļþ£¬È¨Ï޽ϴ󣬷ÖÅä´Ë½ÇɫȨÏÞ¸øÊý¾Ý¿âÓû§Ê±ÐèÉóÉ÷˼¿¼¡£


²Î¿¼Á´½Ó


http://paper.tuisec.win/detail/66d2b3ec28c7239