LWN.net Logo

PostgreSQL: privilege escalation

Package(s):postgresql CVE #(s):CVE-2006-0553
Created:February 15, 2006 Updated:February 19, 2006
Description: From the advisory: "By issuing SET ROLE with a specially crafted argument, it is possible for any logged-in database user to acquire the privileges of any other database user, including superusers. Database superuser status allows access to the machine's filesystem and hence might be used to mount remote attacks against the rest of the server's operating system." This problem has been fixed in PostgreSQL releases 8.0.7, 7.4.12, and 7.3.14.
Alerts:
OpenPKG OpenPKG-SA-2006.004 2006-02-19

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds