PT-2002-2366 · Postgresql · Postgresql

Published

2002-10-03

·

Updated

2017-07-11

·

CVE-2002-1642

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PostgreSQL versions 7.2.1 through 7.2.2
Description The issue allows local users to cause a denial of service, resulting in data loss, by deleting transaction log (pg clog) data via the VACUUM command.
Recommendations For versions 7.2.1 and 7.2.2, consider restricting access to the VACUUM command to prevent unauthorized data deletion until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1642

Affected Products

Postgresql