[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-0061Date: (C)2014-05-20   (M)2023-12-22


The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to gain privileges via a function that is (1) defined in another language or (2) not allowed to be directly called by the user due to permissions.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.5
Exploit Score: 8.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: SINGLE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECUNIA-61307
APPLE-SA-2014-10-16-3
DSA-2864
DSA-2865
RHSA-2014:0211
RHSA-2014:0221
RHSA-2014:0249
RHSA-2014:0469
USN-2120-1
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://support.apple.com/kb/HT6448
http://wiki.postgresql.org/wiki/20140220securityrelease
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
http://www.postgresql.org/about/news/1506/
https://support.apple.com/kb/HT6536
openSUSE-SU-2014:0345
openSUSE-SU-2014:0368

CPE    57
cpe:/a:postgresql:postgresql:8.4.7
cpe:/a:postgresql:postgresql:8.4.6
cpe:/a:postgresql:postgresql:8.4.9
cpe:/a:postgresql:postgresql:8.4.8
...
CWE    1
CWE-264
OVAL    13
oval:org.secpod.oval:def:1600166
oval:org.secpod.oval:def:203041
oval:org.secpod.oval:def:203046
oval:org.secpod.oval:def:33749
...

© SecPod Technologies