PT-2007-3480 · Postgresql+1 · Postgresql+1

Published

2007-04-24

·

Updated

2019-08-09

·

CVE-2007-2138

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostgreSQL versions prior to 7.3.19 PostgreSQL versions 7.4.x prior to 7.4.17 PostgreSQL versions 8.0.x prior to 8.0.13 PostgreSQL versions 8.1.x prior to 8.1.9 PostgreSQL versions 8.2.x prior to 8.2.4
Description The issue allows remote authenticated users to gain the privileges of the function owner when permitted to call a SECURITY DEFINER function, related to "search path settings."
Recommendations For versions prior to 7.3.19, update to version 7.3.19 or later. For versions 7.4.x prior to 7.4.17, update to version 7.4.17 or later. For versions 8.0.x prior to 8.0.13, update to version 8.0.13 or later. For versions 8.1.x prior to 8.1.9, update to version 8.1.9 or later. For versions 8.2.x prior to 8.2.4, update to version 8.2.4 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-2138
DLA-1874-1
DSA-1309-1
DSA-1311-1
RHSA-2007:0336
RHSA-2007:0337
RHSA-2007_0336

Affected Products

Postgresql
Red Hat