PT-2006-1617 · Postgresql · Postgresql

Akio Ishida

·

Publicado

2006-02-14

·

Atualizado

2018-10-19

·

CVE-2006-0553

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostgreSQL versions 8.1.0 through 8.1.2
Description The issue allows authenticated database users to gain additional privileges via knowledge of the backend protocol by using a crafted SET ROLE to other database users. This is achieved through a bug in the handling of SET ROLE, which enables escalation of privileges to any other database user, including superuser. A valid login is required to exploit this issue.
Recommendations For PostgreSQL versions 8.1.0 through 8.1.2, consider restricting the use of the SET ROLE command until a patch is available to prevent privilege escalation. As a temporary workaround, limit the privileges of authenticated database users to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-0553

Produtos afetados

Postgresql