1.5
CVSSv2

CVE-2006-0678

Published: 14/02/2006 Updated: 19/10/2018
CVSS v2 Base Score: 1.5 | Impact Score: 2.9 | Exploitability Score: 2.7
VMScore: 134
Vector: AV:L/AC:M/Au:S/C:N/I:N/A:P

Vulnerability Summary

PostgreSQL 7.3.x prior to 7.3.14, 7.4.x prior to 7.4.12, 8.0.x prior to 8.0.7, and 8.1.x prior to 8.1.3, when compiled with Asserts enabled, allows local users to cause a denial of service (server crash) via a crafted SET SESSION AUTHORIZATION command, a different vulnerability than CVE-2006-0553.

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql 7.3.11

postgresql postgresql 7.3.12

postgresql postgresql 7.3.8

postgresql postgresql 7.3.9

postgresql postgresql 7.4.4

postgresql postgresql 7.4.5

postgresql postgresql 8.0.2

postgresql postgresql 8.0.3

postgresql postgresql 8.0.4

postgresql postgresql 7.3.13

postgresql postgresql 7.3.2

postgresql postgresql 7.3.3

postgresql postgresql 7.4

postgresql postgresql 7.4.1

postgresql postgresql 7.4.6

postgresql postgresql 7.3.1

postgresql postgresql 7.3.10

postgresql postgresql 7.3.6

postgresql postgresql 7.3.7

postgresql postgresql 7.4.2

postgresql postgresql 7.4.3

postgresql postgresql 8.0

postgresql postgresql 8.0.1

postgresql postgresql 8.1.2

postgresql postgresql 7.4.7

postgresql postgresql 8.0.5

postgresql postgresql 8.0.6

postgresql postgresql 7.3

postgresql postgresql 7.3.4

postgresql postgresql 7.3.5

postgresql postgresql 7.4.10

postgresql postgresql 7.4.11

postgresql postgresql 7.4.8

postgresql postgresql 7.4.9

postgresql postgresql 8.1

postgresql postgresql 8.1.1

Vendor Advisories

Akio Ishida discovered that the SET SESSION AUTHORIZATION command did not properly verify the validity of its argument An authenticated PostgreSQL user could exploit this to crash the server ...