PT-2014-3462 · Postgresql+1 · Postgresql+1

Publicado

2014-03-28

·

Atualizado

2024-06-15

·

CVE-2014-0067

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostgreSQL versions 9.3.3 and earlier
Description The issue allows local users to gain privileges by leveraging access to a database cluster used for test suites. This is due to the "make check" command not properly invoking initdb to specify authentication requirements for the cluster. Unauthenticated users may gain access to the database server during the "make check" process.
Recommendations For PostgreSQL versions 9.3.3 and earlier, consider restricting access to the database cluster used for test suites until a proper fix is applied. As a temporary workaround, ensure that only authorized users have access to the "make check" command to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-0067
DLA-0019-1
DSA-2864-1
DSA-2865-1
MGASA-2014-0205
MGASA-2014-0222
OPENSUSE-SU-2024:10030-1
OPENSUSE-SU-2024:10256-1
OPENSUSE-SU-2024:10273-1

Produtos afetados

Postgresql
Suse