CNNVD-202511-1628 Information

CNNVD ID

CNNVD-202511-1628

CVE-2025-12817

  • CNNVD Published: 2025-11-13

Description (Chinese)

PostgreSQL是PostgreSQL组织的一套自由的对象关系型数据库管理系统。该系统支持大部分SQL标准并且提供了许多其他特性,例如外键、触发器、视图等。 PostgreSQL存在安全漏洞,该漏洞源于CREATE STATISTICS命令缺少授权,可能导致拒绝服务攻击。以下版本受到影响:18.1之前版本、17.7之前版本、16.11之前版本、15.15之前版本、14.20之前版本和13.23之前版本。

Description (English)

PostgreSQL is a free client relationship database management system organized by PostgreSQL. The system supports most SQL standards and provides many other features, such as external keys, triggers, views, etc. There is a security loophole in PostgreSQL, which stems from the lack of authorization for the CREATE STATISTICS order, which could lead to the denial of service attacks. The following versions were affected: pre- 18.1, pre-17.7, pre-16.11, pre-15, pre-14.20 and pre-13.23.

Hazard Level

Critical

Vulnerability Type

其他

Affected Vendor

PostgreSQL

Published

2025-11-13

Last Modified

2026-02-24

References

https://www.postgresql.org/support/security/CVE-2025-12817/ https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-12817

Patch

https://www.postgresql.org/support/security/CVE-2025-12817/

Share on: