← All CVEs

CVE-2013-1899

medium · 6.5

Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a denial of service (file corruption), and allows remote authenticated users to modify configuration settings and execute arbitrary code, via a connection request using a database name that begins with a "-" (hyphen).

6.5
CVSS
54.3%
EPSS (exploit prob.)
99th
EPSS percentile
2013-04-04
Published

AV:N/AC:L/Au:S/C:P/I:P/A:P

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
postgresqlpostgresql9.2
postgresqlpostgresql9.2.1
postgresqlpostgresql9.2.2
postgresqlpostgresql9.2.3
postgresqlpostgresql9.1
postgresqlpostgresql9.1.1
postgresqlpostgresql9.1.2
postgresqlpostgresql9.1.3
postgresqlpostgresql9.1.4
postgresqlpostgresql9.1.5
postgresqlpostgresql9.1.6
postgresqlpostgresql9.1.7
postgresqlpostgresql9.1.8
postgresqlpostgresql9.0
postgresqlpostgresql9.0.1
postgresqlpostgresql9.0.2
postgresqlpostgresql9.0.3
postgresqlpostgresql9.0.4
postgresqlpostgresql9.0.5
postgresqlpostgresql9.0.6
postgresqlpostgresql9.0.7
postgresqlpostgresql9.0.8
postgresqlpostgresql9.0.9
postgresqlpostgresql9.0.10
postgresqlpostgresql9.0.11
postgresqlpostgresql9.0.12
canonicalubuntu_linux8.04
canonicalubuntu_linux10.04
canonicalubuntu_linux11.10
canonicalubuntu_linux12.04
canonicalubuntu_linux12.10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-1899