CVE-2010-1447 describes a critical vulnerability in the Safe Perl module (versions 2.26 and earlier), specifically impacting PostgreSQL versions 7.4 through 9.0 Beta. This flaw allows authenticated attackers to bypass security restrictions in Safe::reval and Safe::rdo, enabling arbitrary code injection and execution. With a CVSS score of 8.5, this vulnerability presents a high risk due to its network-based attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation is reported, and it's not on the KEV list, its high FAUCET Risk Score and community discussion indicate a notable concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.4CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:7.4:*:*:*:*:*:*:* | ||
7.4.1CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:7.4.1:*:*:*:*:*:*:* | ||
7.4.2CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:7.4.2:*:*:*:*:*:*:* | ||
7.4.3CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:7.4.3:*:*:*:*:*:*:* | ||
7.4.4CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:7.4.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.