Race condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE commands in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allows remote authenticated users to create an unauthorized index or read portions of unauthorized tables by creating or deleting a table with the same name during the timing window.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2014-0062 from the MITRE CVE dictionary dictionary and NIST NVD.
Base Score | 3.5 |
---|---|
Base Metrics | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Access Vector | Network |
Access Complexity | Medium |
Authentication | Single |
Confidentiality Impact | Partial |
Integrity Impact | None |
Availability Impact | None |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Red Hat Enterprise Linux 6 (postgresql) | RHSA-2014:0211 | 2014-02-25 |
Red Hat Enterprise Linux 5 (postgresql84) | RHSA-2014:0211 | 2014-02-25 |
CloudForms Management Engine 5.4 (postgresql92-postgresql) | RHSA-2014:0469 | 2014-05-12 |
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 (postgresql92-postgresql) | RHSA-2014:0221 | 2014-02-27 |
Red Hat Enterprise Linux 5 (postgresql) | RHSA-2014:0249 | 2014-03-04 |
Platform | Package | State |
---|---|---|
Red Hat Enterprise Linux 7 | postgresql | Not affected |