חזרה לפיד
newsמקור: The Hacker News4.9.2026

PostgreSQL תיקנה פגיעות בת 12 שנים שאפשרה הרצת קוד כמשתמש המערכת

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

PostgreSQL תיקנה פגיעות בת 12 שנים שאפשרה הרצת קוד כמשתמש המערכת

◆ סיכום AI

PostgreSQL פרסמה עדכוני אבטחה לתיקון פגיעות חמורה המאפשרת למשתמש בעל הרשאת REPLICATION להריץ קוד שרירותי כמשתמש מערכת ההפעלה המריץ את שרת מסד הנתונים. הפגיעות, המסומנת כ-CVE-2026-6471, הייתה קיימת מאז 2014 ומדגישה את החשיבות בעדכון שוטף של מערכות קריטיות.

# מהמקור

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are

#postgresql#vulnerability#cve#database-security
קרא במקור