Release date:
Updated on:
Affected Systems:
PostgreSQL 8.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65723
CVE (CAN) ID: CVE-2014-0060
PostgreSQL is an advanced object-relational database management system that supports extended SQL standard subsets.
PostgreSQL 9.3.3, 9.2.7, 9.1.12, 9.0.16, and earlier than 8.4.20 have security vulnerabilities... the without admin option restriction can be bypassed. Attackers can exploit this vulnerability to obtain administrator privileges and revoke access permissions from other users.
<* Source: Noah Misch
Jonas Sundman
Link: https://bugzilla.redhat.com/show_bug.cgi? CVE-2014-0060
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PostgreSQL
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.postgresql.org
PostgreSQL details: click here
PostgreSQL: click here
PostgreSQL cache details
Compiling PostgreSQL on Windows
Configuration and installation of LAPP (Linux + Apache + PostgreSQL + PHP) Environment in Ubuntu
Install and configure phppgAdmin on Ubuntu