Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-0067

Overview

Vulnerability Score 4.6 4.6
CVE Id CVE-2014-0067
Last Modified 18 Sep 2015 09:59:07
Published 31 Mar 2014 10:58:15
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2014-0067

Summary

The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.

Vulnerable Systems

Application

  • Postgresql 8.4.1

  • Postgresql 8.4.10

  • Postgresql 8.4.11

  • Postgresql 8.4.12

  • Postgresql 8.4.13

  • Postgresql 8.4.14

  • Postgresql 8.4.15

  • Postgresql 8.4.16

  • Postgresql 8.4.17

  • Postgresql 8.4.18

  • Postgresql 8.4.19

  • Postgresql 8.4.2

  • Postgresql 8.4.3

  • Postgresql 8.4.4

  • Postgresql 8.4.5

  • Postgresql 8.4.6

  • Postgresql 8.4.7

  • Postgresql 8.4.8

  • Postgresql 8.4.9

  • Postgresql 9.0

  • Postgresql 9.0.1

  • Postgresql 9.0.10

  • Postgresql 9.0.11

  • Postgresql 9.0.12

  • Postgresql 9.0.13

  • Postgresql 9.0.14

  • Postgresql 9.0.15

  • Postgresql 9.0.2

  • Postgresql 9.0.3

  • Postgresql 9.0.4

  • Postgresql 9.0.5

  • Postgresql 9.0.6

  • Postgresql 9.0.7

  • Postgresql 9.0.8

  • Postgresql 9.0.9

  • Postgresql 9.1

  • Postgresql 9.1.1

  • Postgresql 9.1.10

  • Postgresql 9.1.11

  • Postgresql 9.1.2

  • Postgresql 9.1.3

  • Postgresql 9.1.4

  • Postgresql 9.1.5

  • Postgresql 9.1.6

  • Postgresql 9.1.7

  • Postgresql 9.1.8

  • Postgresql 9.1.9

  • Postgresql 9.2

  • Postgresql 9.2.1

  • Postgresql 9.2.2

  • Postgresql 9.2.3

  • Postgresql 9.2.4

  • Postgresql 9.2.5

  • Postgresql 9.2.6

  • Postgresql 9.3

  • Postgresql 9.3.1

  • Postgresql 9.3.2


References

CONFIRM - http://www.postgresql.org/about/news/1506/

DEBIAN - DSA-2865

DEBIAN - DSA-2864

CONFIRM - http://wiki.postgresql.org/wiki/20140220securityrelease

CONFIRM - https://support.apple.com/kb/HT205031

APPLE - APPLE-SA-2015-08-13-2

CONFIRM - https://support.apple.com/HT205219

APPLE - APPLE-SA-2015-09-16-4


Last Updated: 27 May 2016 11:09:52