PT-2007-3480 · Postgresql+1 · Postgresql+1

Publicado

2007-04-24

·

Atualizado

2019-08-09

·

CVE-2007-2138

CVSS v2.0

6.0

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostgreSQL versions prior to 7.3.19 PostgreSQL versions 7.4.x prior to 7.4.17 PostgreSQL versions 8.0.x prior to 8.0.13 PostgreSQL versions 8.1.x prior to 8.1.9 PostgreSQL versions 8.2.x prior to 8.2.4
Description The issue allows remote authenticated users to gain the privileges of the function owner when permitted to call a SECURITY DEFINER function, related to "search path settings."
Recommendations For versions prior to 7.3.19, update to version 7.3.19 or later. For versions 7.4.x prior to 7.4.17, update to version 7.4.17 or later. For versions 8.0.x prior to 8.0.13, update to version 8.0.13 or later. For versions 8.1.x prior to 8.1.9, update to version 8.1.9 or later. For versions 8.2.x prior to 8.2.4, update to version 8.2.4 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-2138
DLA-1874-1
DSA-1309-1
DSA-1311-1
RHSA-2007:0336
RHSA-2007:0337
RHSA-2007_0336

Produtos afetados

Postgresql
Red Hat