PT-2008-1572 · Postgresql+1 · Postgresql+1

Published

2008-01-09

·

Updated

2024-06-15

·

CVE-2007-6600

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostgreSQL versions 7.3 through 7.3.20 PostgreSQL versions 7.4 through 7.4.18 PostgreSQL versions 8.0 through 8.0.14 PostgreSQL versions 8.1 through 8.1.10 PostgreSQL versions 8.2 through 8.2.5
Description The issue allows remote authenticated users to gain privileges due to the use of superuser privileges instead of table owner privileges for certain operations within index functions. This includes VACUUM and ANALYZE operations, as well as support for SET ROLE and SET SESSION AUTHORIZATION within index functions. Additionally, vulnerabilities in how ANALYZE executes user-defined functions that are part of expression indexes can allow users to gain superuser privileges, requiring a valid login with permissions to create functions and tables to exploit.
Recommendations For PostgreSQL versions 7.3 through 7.3.20, update to version 7.3.21 or later. For PostgreSQL versions 7.4 through 7.4.18, update to version 7.4.19 or later. For PostgreSQL versions 8.0 through 8.0.14, update to version 8.0.15 or later. For PostgreSQL versions 8.1 through 8.1.10, update to version 8.1.11 or later. For PostgreSQL versions 8.2 through 8.2.5, update to version 8.2.6 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6600
DSA-1460-1
DSA-1463-1
OPENSUSE-SU-2024:10030-1
OPENSUSE-SU-2024:10256-1
OPENSUSE-SU-2024:10273-1
RHSA-2008:0038
RHSA-2008:0039
RHSA-2008:0040
RHSA-2008_0038

Affected Products

Postgresql
Red Hat