The vendor explicitly identifies these products as affected by this CVE.
- postgresql as a component of Red Hat Enterprise Linux 10
- postgresql-contrib as a component of Red Hat Enterprise Linux 10
- postgresql-docs as a component of Red Hat Enterprise Linux 10
- postgresql-plperl as a component of Red Hat Enterprise Linux 10
- postgresql-plpython3 as a component of Red Hat Enterprise Linux 10
- postgresql-pltcl as a component of Red Hat Enterprise Linux 10
- postgresql-private-devel as a component of Red Hat Enterprise Linux 10
- postgresql-private-libs as a component of Red Hat Enterprise Linux 10
- postgresql-server as a component of Red Hat Enterprise Linux 10
- postgresql-server-devel as a component of Red Hat Enterprise Linux 10
- postgresql-static as a component of Red Hat Enterprise Linux 10
- postgresql-test as a component of Red Hat Enterprise Linux 10
- Summary
- A flaw was found in PostgreSQL psql. During the `COPY FROM STDIN` operation, untrusted data can be mistakenly interpreted as psql commands if an error injection causes the command to fail prematurely. This could allow an attacker to achieve arbitrary command execution. Successful exploitation requires the attacker to control both the server and the data being copied, or to leverage a coincidental error while controlling only the data.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
