|
|
| |
|
| |
PostgreSQL: privilege escalation
| Package(s): | postgresql |
CVE #(s): | CVE-2006-0553
|
| Created: | February 15, 2006 |
Updated: | February 19, 2006 |
| Description: |
From the advisory: "By issuing SET ROLE with a specially crafted argument, it is possible
for any logged-in database user to acquire the privileges of any other
database user, including superusers. Database superuser status allows
access to the machine's filesystem and hence might be used to mount
remote attacks against the rest of the server's operating system." This problem has been fixed in PostgreSQL releases 8.0.7, 7.4.12, and 7.3.14. |
| Alerts: |
|
( Log in to post comments)
|
|
|