Unrated severityNVD Advisory· Published Apr 4, 2013· Updated Apr 29, 2026
CVE-2013-1899
CVE-2013-1899
Description
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a denial of service (file corruption), and allows remote authenticated users to modify configuration settings and execute arbitrary code, via a connection request using a database name that begins with a "-" (hyphen).
Affected products
31cpe:2.3:a:postgresql:postgresql:9.0:*:*:*:*:*:*:*+ 25 more
- cpe:2.3:a:postgresql:postgresql:9.0:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.1:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.2:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:postgresql:postgresql:9.2.3:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:*+ 4 more
- cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:8.04:-:lts:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
18- www.postgresql.org/about/news/1456/nvdVendor Advisory
- www.postgresql.org/support/security/faq/2013-04-04/nvdVendor Advisory
- lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlnvd
- lists.apple.com/archives/security-announce/2013/Sep/msg00004.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2013-April/101519.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2013-April/102806.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2013-04/msg00007.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2013-04/msg00008.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2013-04/msg00011.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2013-04/msg00012.htmlnvd
- support.apple.com/kb/HT5880nvd
- support.apple.com/kb/HT5892nvd
- www.debian.org/security/2013/dsa-2658nvd
- www.mandriva.com/security/advisoriesnvd
- www.postgresql.org/docs/current/static/release-9-0-13.htmlnvd
- www.postgresql.org/docs/current/static/release-9-1-9.htmlnvd
- www.postgresql.org/docs/current/static/release-9-2-4.htmlnvd
- www.ubuntu.com/usn/USN-1789-1nvd
News mentions
0No linked articles in our index yet.