PT-2013-6353 · Postgresql+1 · Postgresql+1

Noah Misch

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2013-1901

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PostgreSQL versions 9.2.x through 9.2.3 PostgreSQL versions 9.1.x through 9.1.8
Description The issue allows remote authenticated users to bypass intended backup restrictions. This can be achieved by calling the (1) pg start backup or (2) pg stop backup functions. An unprivileged user can run commands that could interfere with in-progress backups. The vulnerability may lead to a violation of confidentiality, integrity, and availability of protected information and can be exploited remotely by an authenticated attacker.
Recommendations For PostgreSQL versions 9.2.x through 9.2.3, update to version 9.2.4 or later. For PostgreSQL versions 9.1.x through 9.1.8, update to version 9.1.9 or later. As a temporary workaround, consider restricting access to the pg start backup and pg stop backup functions until a patch is available.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04511
BDU:2015-04512
BDU:2015-04513
BDU:2015-04514
CVE-2013-1901
DSA-2658-1
OPENSUSE-SU-2013_0627-1
OPENSUSE-SU-2013_0628-1
OPENSUSE-SU-2013_0635-1
OPENSUSE-SU-2024:10030-1
OPENSUSE-SU-2024:10256-1
OPENSUSE-SU-2024:10273-1

Affected Products

Postgresql
Suse