PostgreSQLí§Òâ´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-03-27

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-9193£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


ÊÜÓ°Ïì°æ±¾£º 

PostgreSQL >=9.3


Îó²î¸ÅÊö


¿ËÈÕ£¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±Åû¶ÁËPostgreSQLÌáȨ´úÂëÖ´ÐÐÎó²îµÄÎó²îϸ½Ú£¬£¬£¬£¬¾ßÓÐÊý¾Ý¿âЧÀͶËÎļþ¶ÁȨÏ޵Ĺ¥»÷ÕßʹÓôËÎó²î£¬£¬£¬£¬¿ÉÖ´ÐÐí§ÒâϵͳÏÂÁî¡£¡£¡£¡£¡£¡£¡£

PostgreSQLÊÇÒ»¿î¹¦Ð§Ç¿Ê¢µÄÊý¾Ý¿âÈí¼þ£¬£¬£¬£¬¿ÉÔËÐÐÔÚËùÓÐÖ÷Á÷²Ù×÷ϵͳÉÏ£¬£¬£¬£¬°üÀ¨Linux¡¢Windows¡¢Mac OS XµÈ¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÅû¶µÄÎó²î±£´æÓÚµ¼Èëµ¼³öÊý¾ÝµÄÏÂÁî¡°COPY TO/FROM PROGRAM¡±ÖУ¬£¬£¬£¬¡°pg_read_server_files¡±×éÄÚÓû§Ö´ÐÐÉÏÊöÏÂÁîºó£¬£¬£¬£¬¿É»ñÈ¡Êý¾Ý¿â³¬µÈÓû§È¨ÏÞ£¬£¬£¬£¬´Ó¶øÖ´ÐÐí§ÒâϵͳÏÂÁî¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ¹Ù·½ÐÞ¸´´ËÎó²îµÄÍýÏë¡£¡£¡£¡£¡£¡£¡£pg_read_server_files¡¢pg_write_server_files¡¢pg_execute_server_program ½Çɫɿ¼°µ½¶ÁдÊý¾Ý¿âЧÀͶËÎļþ£¬£¬£¬£¬È¨Ï޽ϴ󣬣¬£¬£¬·ÖÅɴ˽ÇɫȨÏÞ¸øÊý¾Ý¿âÓû§Ê±ÐèÉóÉ÷˼Á¿¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


http://paper.tuisec.win/detail/66d2b3ec28c7239