CVE-2020-14349
Publication date 17 August 2020
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.
Status
| Package | Ubuntu Release | Status | 
|---|---|---|
| postgresql-10 | 20.04 LTS focal | Not in release | 
| 18.04 LTS bionic | 
                              
                               
                                Fixed 10.14-0ubuntu0.18.04.1 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
| postgresql-12 | 20.04 LTS focal | 
                              
                               
                                Fixed 12.4-0ubuntu0.20.04.1 
                                
                               
                             |      
                          
                            
                          
                        
                      
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
| postgresql-9.1 | 20.04 LTS focal | Not in release | 
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
| postgresql-9.3 | 20.04 LTS focal | Not in release | 
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | 
                              
                               
                                Not affected 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| postgresql-9.5 | 20.04 LTS focal | Not in release | 
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | 
                              
                               
                                Not affected 
                                
                               
                             |      
                          
                            
                          
                        
                      |
| 14.04 LTS trusty | Not in release | 
Patch details
| Package | Patch details | 
|---|---|
| postgresql-12 | 
Severity score breakdown
| Parameter | Value | 
|---|---|
| Base score | 
                      
                      
                         | 
                  
| Attack vector | Network | 
| Attack complexity | High | 
| Privileges required | Low | 
| User interaction | Required | 
| Scope | Unchanged | 
| Confidentiality | High | 
| Integrity impact | High | 
| Availability impact | High | 
| Vector | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H | 
References
Related Ubuntu Security Notices (USN)
- USN-4472-1
 - PostgreSQL vulnerabilities
 - 25 August 2020