Release date:
Updated on:
Affected Systems:
PostgreSQL 8.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65721
CVE (CAN) ID: CVE-2014-0067
PostgreSQL is an advanced object-relational database management system that supports extended SQL standard subsets.
When PostgreSQL versions earlier than 9.3.3, 9.2.7, 9.1.12, 9.0.16, and 8.4.20 run the "make check" regression test in the constructor tree, the server process allows users on the same machine to Log On As superusers, another local user can also obtain the permissions of the operating system user.
<* Source: Noah Misch
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 1065863
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PostgreSQL
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.postgresql.org
PostgreSQL details: click here
PostgreSQL: click here
PostgreSQL cache details
Compiling PostgreSQL on Windows
Configuration and installation of LAPP (Linux + Apache + PostgreSQL + PHP) Environment in Ubuntu
Install and configure phppgAdmin on Ubuntu