4
CVSSv2

CVE-2014-0060

Published: 31/03/2014 Updated: 16/12/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 358
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

PostgreSQL prior to 8.4.20, 9.0.x prior to 9.0.16, 9.1.x prior to 9.1.12, 9.2.x prior to 9.2.7, and 9.3.x prior to 9.3.3 does not properly enforce the ADMIN OPTION restriction, which allows remote authenticated members of a role to add or remove arbitrary users to that role by calling the SET ROLE command before the associated GRANT command.

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql 9.2

postgresql postgresql 9.1.8

postgresql postgresql 9.1.1

postgresql postgresql 9.0.9

postgresql postgresql 9.0.12

postgresql postgresql 9.0.2

postgresql postgresql 8.4.7

postgresql postgresql 8.4.6

postgresql postgresql 8.4.13

postgresql postgresql 9.2.2

postgresql postgresql 9.2.1

postgresql postgresql 9.1.3

postgresql postgresql 9.1.4

postgresql postgresql 9.1

postgresql postgresql 9.0.4

postgresql postgresql 9.0.3

postgresql postgresql 8.4.9

postgresql postgresql 8.4.8

postgresql postgresql 8.4.15

postgresql postgresql 8.4.14

postgresql postgresql 9.3.1

postgresql postgresql 9.3

postgresql postgresql 9.1.9

postgresql postgresql 9.0.15

postgresql postgresql 9.1.5

postgresql postgresql 9.1.2

postgresql postgresql 9.0.6

postgresql postgresql 9.0.5

postgresql postgresql 9.0.10

postgresql postgresql 9.0

postgresql postgresql 8.4.3

postgresql postgresql 8.4.2

postgresql postgresql 8.4.16

postgresql postgresql 8.4.1

postgresql postgresql 9.3.2

postgresql postgresql 9.1.11

postgresql postgresql 9.1.10

postgresql postgresql 8.4.12

postgresql postgresql 9.2.6

postgresql postgresql 9.2.5

postgresql postgresql 9.0.14

postgresql postgresql 9.0.13

postgresql postgresql 9.1.7

postgresql postgresql 9.1.6

postgresql postgresql 9.0.8

postgresql postgresql 9.0.7

postgresql postgresql 9.0.11

postgresql postgresql 9.0.1

postgresql postgresql 8.4.5

postgresql postgresql 8.4.4

postgresql postgresql 8.4.11

postgresql postgresql 8.4.10

postgresql postgresql 9.2.4

postgresql postgresql 9.2.3

postgresql postgresql

postgresql postgresql 8.4.18

postgresql postgresql 8.4.17

Vendor Advisories

Several security issues were fixed in PostgreSQL ...
Various vulnerabilities were discovered in PostgreSQL: CVE-2014-0060 Shore up GRANT WITH ADMIN OPTION restrictions (Noah Misch) Granting a role without ADMIN OPTION is supposed to prevent the grantee from adding or removing members from the granted role, but this restriction was easily bypassed by doing SET ROLE first The securit ...
Various vulnerabilities were discovered in PostgreSQL: CVE-2014-0060 Shore up GRANT WITH ADMIN OPTION restrictions (Noah Misch) Granting a role without ADMIN OPTION is supposed to prevent the grantee from adding or removing members from the granted role, but this restriction was easily bypassed by doing SET ROLE first The securit ...
Multiple stack-based buffer overflow flaws were found in the date/time implementation of PostgreSQL An authenticated database user could provide a specially crafted date/time value that, when processed, could cause PostgreSQL to crash or, potentially, execute arbitrary code with the permissions of the user running PostgreSQL (CVE-2014-0063) Multi ...
Multiple stack-based buffer overflow flaws were found in the date/time implementation of PostgreSQL An authenticated database user could provide a specially crafted date/time value that, when processed, could cause PostgreSQL to crash or, potentially, execute arbitrary code with the permissions of the user running PostgreSQL (CVE-2014-0063) Multi ...
PostgreSQL before 8420, 90x before 9016, 91x before 9112, 92x before 927, and 93x before 933 does not properly enforce the ADMIN OPTION restriction, which allows remote authenticated members of a role to add or remove arbitrary users to that role by calling the SET ROLE command before the associated GRANT command ...