4 ms·
So if I have no databases that start with "-", I'm not vulnerable? Didn't quite understand what they meant by that.
by dkulchenko 14y ago
So if I have no databases that start with "-", I'm not vulnerable? Didn't quite understand what they meant by that.
- sgift 14y agoJust from the quote cited by octo_t I would read that you are still vulnerable: A malicious database user could craft a _connection string_ which contains a database name starting with -. There's no hint that the database has to exist on your server for this to work, so I would read it could be a complete bogus request and still damage your files.
- qompiler 14y ago/* Is this all it takes? */ PQconnectdb("host=127.0.0.1 dbname=-exploit user=postgres password=postgres port=5432");
- jeltz 14y agoYes, but that wouldn't do anything harmful. Something like dbname="-r /var/lib/postgresql/9.1/main/pg_clog/0000" would be required to cause any harm. I have not tested it in practice but that should cause the server to overwrite the file with log output. EDIT: They are not overwritten but just appended to.
- jsaxton86 14y agoFrom the FAQ originally shared by edwinvlieg, you are still vulnerable: The vulnerability allows users to use a command-line switch for a PostgreSQL connection intended for single-user recovery mode while PostgreSQL is running in normal, multiuser mode. This can be used to harm the server.
- masklinn 14y agoNope. Looking at the release notes: > Fix insecure parsing of server command-line switches (Mitsumasa Kondo, Kyotaro Horiguchi) So I assume command-line switch parsing is somehow involved in parsing the connection string (probably because the same connection strings can be used from API and from CLI?), I guess a database name with a leading `-` can be interpreted as a switch and execute corrupting commands. edit: according to the dedicated FAQ: > The vulnerability allows users to use a command-line switch for a PostgreSQL connection intended for single-user recovery mode while PostgreSQL is running in normal, multiuser mode. This can be used to harm the server.