PT-2010-3596 · Postgresql+1 · Postgresql+1

Published

2010-05-19

·

Updated

2017-09-19

·

CVE-2010-1975

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PostgreSQL versions 7.4 through 7.4.28 PostgreSQL versions 8.0 through 8.0.24 PostgreSQL versions 8.1 through 8.1.20 PostgreSQL versions 8.2 through 8.2.16 PostgreSQL versions 8.3 through 8.3.10 PostgreSQL versions 8.4 through 8.4.3
Description The issue allows remote authenticated users to remove arbitrary parameter settings via certain statements, effectively bypassing settings that should be enforced. An unprivileged database user can exploit this to remove superuser-only settings applied to their account, which were set by a superuser using ALTER USER.
Recommendations For PostgreSQL versions 7.4 through 7.4.28, update to version 7.4.29 or later. For PostgreSQL versions 8.0 through 8.0.24, update to version 8.0.25 or later. For PostgreSQL versions 8.1 through 8.1.20, update to version 8.1.21 or later. For PostgreSQL versions 8.2 through 8.2.16, update to version 8.2.17 or later. For PostgreSQL versions 8.3 through 8.3.10, update to version 8.3.11 or later. For PostgreSQL versions 8.4 through 8.4.3, update to version 8.4.4 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1975
DSA-2051-1
RHSA-2010:0428
RHSA-2010:0429
RHSA-2010:0430
RHSA-2010_0428
RHSA-2010_0429
RHSA-2010_0430
RHSA-2026:8756

Affected Products

Postgresql
Red Hat