4.6
CVSSv2

CVE-2014-0067

Published: 31/03/2014 Updated: 16/12/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 411
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The "make check" command for the test suites in PostgreSQL 9.3.3 and previous versions does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.10.4

apple mac os x server 5.0.3

postgresql postgresql 9.1.7

postgresql postgresql 9.1.6

postgresql postgresql 9.0.8

postgresql postgresql 9.1.5

postgresql postgresql 9.1.2

postgresql postgresql 9.1.3

postgresql postgresql 9.0.6

postgresql postgresql 9.0.5

postgresql postgresql 9.0.10

postgresql postgresql 9.0

postgresql postgresql 8.4.3

postgresql postgresql 8.4.2

postgresql postgresql 8.4.16

postgresql postgresql 8.4.1

postgresql postgresql 9.3.2

postgresql postgresql 9.1.11

postgresql postgresql 9.1.10

postgresql postgresql 9.2

postgresql postgresql 9.1.8

postgresql postgresql 9.1.1

postgresql postgresql 9.0.9

postgresql postgresql 9.0.12

postgresql postgresql 9.0.2

postgresql postgresql 8.4.7

postgresql postgresql 8.4.6

postgresql postgresql 8.4.13

postgresql postgresql 8.4.12

postgresql postgresql 9.2.6

postgresql postgresql 9.2.5

postgresql postgresql 9.0.14

postgresql postgresql 9.0.13

postgresql postgresql 9.0.7

postgresql postgresql 9.0.11

postgresql postgresql 9.0.1

postgresql postgresql 8.4.5

postgresql postgresql 8.4.4

postgresql postgresql 8.4.11

postgresql postgresql 8.4.10

postgresql postgresql 9.2.4

postgresql postgresql 9.2.3

postgresql postgresql

postgresql postgresql 8.4.18

postgresql postgresql 8.4.17

postgresql postgresql 9.2.2

postgresql postgresql 9.2.1

postgresql postgresql 9.1.4

postgresql postgresql 9.1

postgresql postgresql 9.0.4

postgresql postgresql 9.0.3

postgresql postgresql 8.4.9

postgresql postgresql 8.4.8

postgresql postgresql 8.4.15

postgresql postgresql 8.4.14

postgresql postgresql 9.3.1

postgresql postgresql 9.3

postgresql postgresql 9.1.9

postgresql postgresql 9.0.15

Vendor Advisories

Various vulnerabilities were discovered in PostgreSQL: CVE-2014-0060 Shore up GRANT WITH ADMIN OPTION restrictions (Noah Misch) Granting a role without ADMIN OPTION is supposed to prevent the grantee from adding or removing members from the granted role, but this restriction was easily bypassed by doing SET ROLE first The securit ...
Various vulnerabilities were discovered in PostgreSQL: CVE-2014-0060 Shore up GRANT WITH ADMIN OPTION restrictions (Noah Misch) Granting a role without ADMIN OPTION is supposed to prevent the grantee from adding or removing members from the granted role, but this restriction was easily bypassed by doing SET ROLE first The securit ...
A buffer overflow flaw was found in the way PostgreSQL handled certain numeric formatting An authenticated database user could use a specially crafted timestamp formatting template to cause PostgreSQL to crash or, under certain conditions, execute arbitrary code with the permissions of the user running PostgreSQL (CVE-2015-0241) A buffer overflow ...
The "make check" command for the test suites in PostgreSQL 933 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster ...