CVE-2020-14350: Canonical Ubuntu Linux

High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.

It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 20.04 only
  • Debian Debian Linux: version 9.0 only
  • Opensuse Leap: version 15.1 only; version 15.2 only
  • PostgreSQL PostgreSQL: from 9.5, before 9.5.23 (fixed in 9.5.23); from 9.6, before 9.6.19 (fixed in 9.6.19); from 10.0, before 10.14 (fixed in 10.14); from 11.0, before 11.9 (fixed in 11.9); from 12.0, before 12.4 (fixed in 12.4)

Published 2020-08-24. Last modified 2026-06-17.