CVE Vulnerabilities

CVE-2009-3230

Published: Sep 17, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
6.5 MODERATE
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7.4.26 does not use the appropriate privileges for the (1) RESET ROLE and (2) RESET SESSION AUTHORIZATION operations, which allows remote authenticated users to gain privileges. NOTE: this is due to an incomplete fix for CVE-2007-6600.

Affected Software

NameVendorStart VersionEnd Version
PostgresqlPostgresql7.4 (including)7.4 (including)
PostgresqlPostgresql7.4.1 (including)7.4.1 (including)
PostgresqlPostgresql7.4.2 (including)7.4.2 (including)
PostgresqlPostgresql7.4.3 (including)7.4.3 (including)
PostgresqlPostgresql7.4.4 (including)7.4.4 (including)
PostgresqlPostgresql7.4.5 (including)7.4.5 (including)
PostgresqlPostgresql7.4.6 (including)7.4.6 (including)
PostgresqlPostgresql7.4.7 (including)7.4.7 (including)
PostgresqlPostgresql7.4.8 (including)7.4.8 (including)
PostgresqlPostgresql7.4.9 (including)7.4.9 (including)
PostgresqlPostgresql7.4.10 (including)7.4.10 (including)
PostgresqlPostgresql7.4.11 (including)7.4.11 (including)
PostgresqlPostgresql7.4.12 (including)7.4.12 (including)
PostgresqlPostgresql7.4.13 (including)7.4.13 (including)
PostgresqlPostgresql7.4.14 (including)7.4.14 (including)
PostgresqlPostgresql7.4.15 (including)7.4.15 (including)
PostgresqlPostgresql7.4.16 (including)7.4.16 (including)
PostgresqlPostgresql7.4.17 (including)7.4.17 (including)
PostgresqlPostgresql7.4.18 (including)7.4.18 (including)
PostgresqlPostgresql7.4.19 (including)7.4.19 (including)
PostgresqlPostgresql7.4.20 (including)7.4.20 (including)
PostgresqlPostgresql7.4.21 (including)7.4.21 (including)
PostgresqlPostgresql7.4.22 (including)7.4.22 (including)
PostgresqlPostgresql7.4.23 (including)7.4.23 (including)
PostgresqlPostgresql7.4.24 (including)7.4.24 (including)
PostgresqlPostgresql7.4.25 (including)7.4.25 (including)
PostgresqlPostgresql8.0 (including)8.0 (including)
PostgresqlPostgresql8.0.1 (including)8.0.1 (including)
PostgresqlPostgresql8.0.2 (including)8.0.2 (including)
PostgresqlPostgresql8.0.3 (including)8.0.3 (including)
PostgresqlPostgresql8.0.4 (including)8.0.4 (including)
PostgresqlPostgresql8.0.5 (including)8.0.5 (including)
PostgresqlPostgresql8.0.6 (including)8.0.6 (including)
PostgresqlPostgresql8.0.7 (including)8.0.7 (including)
PostgresqlPostgresql8.0.8 (including)8.0.8 (including)
PostgresqlPostgresql8.0.9 (including)8.0.9 (including)
PostgresqlPostgresql8.0.10 (including)8.0.10 (including)
PostgresqlPostgresql8.0.11 (including)8.0.11 (including)
PostgresqlPostgresql8.0.12 (including)8.0.12 (including)
PostgresqlPostgresql8.0.13 (including)8.0.13 (including)
PostgresqlPostgresql8.0.14 (including)8.0.14 (including)
PostgresqlPostgresql8.0.15 (including)8.0.15 (including)
PostgresqlPostgresql8.0.16 (including)8.0.16 (including)
PostgresqlPostgresql8.0.17 (including)8.0.17 (including)
PostgresqlPostgresql8.0.18 (including)8.0.18 (including)
PostgresqlPostgresql8.0.19 (including)8.0.19 (including)
PostgresqlPostgresql8.0.20 (including)8.0.20 (including)
PostgresqlPostgresql8.0.21 (including)8.0.21 (including)
PostgresqlPostgresql8.1 (including)8.1 (including)
PostgresqlPostgresql8.1.1 (including)8.1.1 (including)
PostgresqlPostgresql8.1.2 (including)8.1.2 (including)
PostgresqlPostgresql8.1.3 (including)8.1.3 (including)
PostgresqlPostgresql8.1.4 (including)8.1.4 (including)
PostgresqlPostgresql8.1.5 (including)8.1.5 (including)
PostgresqlPostgresql8.1.6 (including)8.1.6 (including)
PostgresqlPostgresql8.1.7 (including)8.1.7 (including)
PostgresqlPostgresql8.1.8 (including)8.1.8 (including)
PostgresqlPostgresql8.1.9 (including)8.1.9 (including)
PostgresqlPostgresql8.1.10 (including)8.1.10 (including)
PostgresqlPostgresql8.1.11 (including)8.1.11 (including)
PostgresqlPostgresql8.1.12 (including)8.1.12 (including)
PostgresqlPostgresql8.1.13 (including)8.1.13 (including)
PostgresqlPostgresql8.1.14 (including)8.1.14 (including)
PostgresqlPostgresql8.1.15 (including)8.1.15 (including)
PostgresqlPostgresql8.1.16 (including)8.1.16 (including)
PostgresqlPostgresql8.2 (including)8.2 (including)
PostgresqlPostgresql8.2.1 (including)8.2.1 (including)
PostgresqlPostgresql8.2.2 (including)8.2.2 (including)
PostgresqlPostgresql8.2.3 (including)8.2.3 (including)
PostgresqlPostgresql8.2.4 (including)8.2.4 (including)
PostgresqlPostgresql8.2.5 (including)8.2.5 (including)
PostgresqlPostgresql8.2.6 (including)8.2.6 (including)
PostgresqlPostgresql8.2.7 (including)8.2.7 (including)
PostgresqlPostgresql8.2.8 (including)8.2.8 (including)
PostgresqlPostgresql8.2.9 (including)8.2.9 (including)
PostgresqlPostgresql8.2.10 (including)8.2.10 (including)
PostgresqlPostgresql8.2.11 (including)8.2.11 (including)
PostgresqlPostgresql8.2.12 (including)8.2.12 (including)
PostgresqlPostgresql8.2.13 (including)8.2.13 (including)
PostgresqlPostgresql8.3.1 (including)8.3.1 (including)
PostgresqlPostgresql8.3.2 (including)8.3.2 (including)
PostgresqlPostgresql8.3.3 (including)8.3.3 (including)
PostgresqlPostgresql8.3.4 (including)8.3.4 (including)
PostgresqlPostgresql8.3.5 (including)8.3.5 (including)
PostgresqlPostgresql8.3.6 (including)8.3.6 (including)
PostgresqlPostgresql8.3.7 (including)8.3.7 (including)
PostgresqlPostgresql8.4 (including)8.4 (including)
Red Hat Enterprise Linux 3RedHatrh-postgresql-0:7.3.21-2*
Red Hat Enterprise Linux 4RedHatpostgresql-0:7.4.26-1.el4_8.1*
Red Hat Enterprise Linux 5RedHatpostgresql-0:8.1.18-2.el5_4.1*
Postgresql-8.1Ubuntudapper*
Postgresql-8.1Ubuntuupstream*
Postgresql-8.3Ubuntuhardy*
Postgresql-8.3Ubuntuintrepid*
Postgresql-8.3Ubuntujaunty*
Postgresql-8.3Ubuntuupstream*

References