Description
The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to gain privileges via a function that is (1) defined in another language or (2) not allowed to be directly called by the user due to permissions.
References (17)
Core 17
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0211.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0221.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0469.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0249.html
Vendor Advisory x_refsource_confirm
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
Vendor Advisory x_refsource_confirm
http://wiki.postgresql.org/wiki/20140220securityrelease
Vendor Advisory x_refsource_confirm
http://www.postgresql.org/about/news/1506/
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2120-1
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT6536
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6448
Third Party Advisory vendor-advisory
x_refsource_apple
http://archives.neohapsis.com/archives/bugtraq/2014-10/0103.html
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2014/dsa-2864
Vendor Advisory x_refsource_confirm
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2014/dsa-2865
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2014-03/msg00018.html
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2014-03/msg00038.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/61307
Scores
EPSS
0.0082
EPSS Percentile
74.7%
Details
CWE
CWE-264
Status
published
Products (50)
postgresql/postgresql
8.4.1
postgresql/postgresql
8.4.2
postgresql/postgresql
8.4.3
postgresql/postgresql
8.4.4
postgresql/postgresql
8.4.5
postgresql/postgresql
8.4.6
postgresql/postgresql
8.4.7
postgresql/postgresql
8.4.8
postgresql/postgresql
8.4.9
postgresql/postgresql
8.4.10
... and 40 more
Published
Mar 31, 2014
Tracked Since
Feb 18, 2026