• CVE-2025-8715

发布时间: 2025年9月5日

修改时间: 2025年9月12日

概要

Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.

CVSS v3 指标

NVD openEuler
Confidentiality High
Attack Vector Network
CVSS评分 N/A 8.8
Attack Complexity Low
Privileges Required None
Scope Unchanged
Integrity High
User Interaction Required
Availability High

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2851 libpq security update 2025年9月22日
KylinSec-SA-2025-2884 libpq security update 2025年9月30日
KylinSec-SA-2025-2894 postgresql security update 2025年9月18日

影响产品

产品 状态
KY3.4-5A postgresql-13 Fixed
V6 postgresql-13 Fixed
KY3.5.3 postgresql-13 Fixed
KY3.5.2 postgresql-13 Fixed