PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly manage session-local state during execution of an index function by a database superuser, which allows remote authenticated users to gain privileges via a table with crafted index functions, as demonstrated by functions that modify (1) search_path or (2) a prepared statement, a related issue to CVE-2007-6600 and CVE-2009-3230.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Postgresql | Postgresql | 7.4.1 (including) | 7.4.1 (including) |
Postgresql | Postgresql | 7.4.2 (including) | 7.4.2 (including) |
Postgresql | Postgresql | 7.4.3 (including) | 7.4.3 (including) |
Postgresql | Postgresql | 7.4.4 (including) | 7.4.4 (including) |
Postgresql | Postgresql | 7.4.5 (including) | 7.4.5 (including) |
Postgresql | Postgresql | 7.4.6 (including) | 7.4.6 (including) |
Postgresql | Postgresql | 7.4.7 (including) | 7.4.7 (including) |
Postgresql | Postgresql | 7.4.8 (including) | 7.4.8 (including) |
Postgresql | Postgresql | 7.4.9 (including) | 7.4.9 (including) |
Postgresql | Postgresql | 7.4.10 (including) | 7.4.10 (including) |
Postgresql | Postgresql | 7.4.11 (including) | 7.4.11 (including) |
Postgresql | Postgresql | 7.4.12 (including) | 7.4.12 (including) |
Postgresql | Postgresql | 7.4.13 (including) | 7.4.13 (including) |
Postgresql | Postgresql | 7.4.14 (including) | 7.4.14 (including) |
Postgresql | Postgresql | 7.4.15 (including) | 7.4.15 (including) |
Postgresql | Postgresql | 7.4.16 (including) | 7.4.16 (including) |
Postgresql | Postgresql | 7.4.17 (including) | 7.4.17 (including) |
Postgresql | Postgresql | 7.4.18 (including) | 7.4.18 (including) |
Postgresql | Postgresql | 7.4.19 (including) | 7.4.19 (including) |
Postgresql | Postgresql | 7.4.20 (including) | 7.4.20 (including) |
Postgresql | Postgresql | 7.4.21 (including) | 7.4.21 (including) |
Postgresql | Postgresql | 7.4.22 (including) | 7.4.22 (including) |
Postgresql | Postgresql | 7.4.23 (including) | 7.4.23 (including) |
Postgresql | Postgresql | 7.4.24 (including) | 7.4.24 (including) |
Postgresql | Postgresql | 7.4.25 (including) | 7.4.25 (including) |
Postgresql | Postgresql | 7.4.26 (including) | 7.4.26 (including) |
Postgresql | Postgresql | 8.0.0 (including) | 8.0.0 (including) |
Postgresql | Postgresql | 8.0.1 (including) | 8.0.1 (including) |
Postgresql | Postgresql | 8.0.2 (including) | 8.0.2 (including) |
Postgresql | Postgresql | 8.0.3 (including) | 8.0.3 (including) |
Postgresql | Postgresql | 8.0.4 (including) | 8.0.4 (including) |
Postgresql | Postgresql | 8.0.5 (including) | 8.0.5 (including) |
Postgresql | Postgresql | 8.0.6 (including) | 8.0.6 (including) |
Postgresql | Postgresql | 8.0.7 (including) | 8.0.7 (including) |
Postgresql | Postgresql | 8.0.8 (including) | 8.0.8 (including) |
Postgresql | Postgresql | 8.0.9 (including) | 8.0.9 (including) |
Postgresql | Postgresql | 8.0.10 (including) | 8.0.10 (including) |
Postgresql | Postgresql | 8.0.11 (including) | 8.0.11 (including) |
Postgresql | Postgresql | 8.0.12 (including) | 8.0.12 (including) |
Postgresql | Postgresql | 8.0.13 (including) | 8.0.13 (including) |
Postgresql | Postgresql | 8.0.14 (including) | 8.0.14 (including) |
Postgresql | Postgresql | 8.0.15 (including) | 8.0.15 (including) |
Postgresql | Postgresql | 8.0.16 (including) | 8.0.16 (including) |
Postgresql | Postgresql | 8.0.17 (including) | 8.0.17 (including) |
Postgresql | Postgresql | 8.0.18 (including) | 8.0.18 (including) |
Postgresql | Postgresql | 8.0.19 (including) | 8.0.19 (including) |
Postgresql | Postgresql | 8.0.20 (including) | 8.0.20 (including) |
Postgresql | Postgresql | 8.0.21 (including) | 8.0.21 (including) |
Postgresql | Postgresql | 8.0.22 (including) | 8.0.22 (including) |
Postgresql | Postgresql | 8.1.0 (including) | 8.1.0 (including) |
Postgresql | Postgresql | 8.1.1 (including) | 8.1.1 (including) |
Postgresql | Postgresql | 8.1.2 (including) | 8.1.2 (including) |
Postgresql | Postgresql | 8.1.3 (including) | 8.1.3 (including) |
Postgresql | Postgresql | 8.1.4 (including) | 8.1.4 (including) |
Postgresql | Postgresql | 8.1.5 (including) | 8.1.5 (including) |
Postgresql | Postgresql | 8.1.6 (including) | 8.1.6 (including) |
Postgresql | Postgresql | 8.1.7 (including) | 8.1.7 (including) |
Postgresql | Postgresql | 8.1.8 (including) | 8.1.8 (including) |
Postgresql | Postgresql | 8.1.9 (including) | 8.1.9 (including) |
Postgresql | Postgresql | 8.1.10 (including) | 8.1.10 (including) |
Postgresql | Postgresql | 8.1.11 (including) | 8.1.11 (including) |
Postgresql | Postgresql | 8.1.12 (including) | 8.1.12 (including) |
Postgresql | Postgresql | 8.1.13 (including) | 8.1.13 (including) |
Postgresql | Postgresql | 8.1.14 (including) | 8.1.14 (including) |
Postgresql | Postgresql | 8.1.15 (including) | 8.1.15 (including) |
Postgresql | Postgresql | 8.1.16 (including) | 8.1.16 (including) |
Postgresql | Postgresql | 8.1.17 (including) | 8.1.17 (including) |
Postgresql | Postgresql | 8.1.18 (including) | 8.1.18 (including) |
Postgresql | Postgresql | 8.2 (including) | 8.2 (including) |
Postgresql | Postgresql | 8.2.1 (including) | 8.2.1 (including) |
Postgresql | Postgresql | 8.2.2 (including) | 8.2.2 (including) |
Postgresql | Postgresql | 8.2.3 (including) | 8.2.3 (including) |
Postgresql | Postgresql | 8.2.4 (including) | 8.2.4 (including) |
Postgresql | Postgresql | 8.2.5 (including) | 8.2.5 (including) |
Postgresql | Postgresql | 8.2.6 (including) | 8.2.6 (including) |
Postgresql | Postgresql | 8.2.7 (including) | 8.2.7 (including) |
Postgresql | Postgresql | 8.2.8 (including) | 8.2.8 (including) |
Postgresql | Postgresql | 8.2.9 (including) | 8.2.9 (including) |
Postgresql | Postgresql | 8.2.10 (including) | 8.2.10 (including) |
Postgresql | Postgresql | 8.2.11 (including) | 8.2.11 (including) |
Postgresql | Postgresql | 8.2.12 (including) | 8.2.12 (including) |
Postgresql | Postgresql | 8.2.13 (including) | 8.2.13 (including) |
Postgresql | Postgresql | 8.2.14 (including) | 8.2.14 (including) |
Postgresql | Postgresql | 8.3.1 (including) | 8.3.1 (including) |
Postgresql | Postgresql | 8.3.2 (including) | 8.3.2 (including) |
Postgresql | Postgresql | 8.3.3 (including) | 8.3.3 (including) |
Postgresql | Postgresql | 8.3.4 (including) | 8.3.4 (including) |
Postgresql | Postgresql | 8.3.5 (including) | 8.3.5 (including) |
Postgresql | Postgresql | 8.3.6 (including) | 8.3.6 (including) |
Postgresql | Postgresql | 8.3.7 (including) | 8.3.7 (including) |
Postgresql | Postgresql | 8.3.8 (including) | 8.3.8 (including) |
Postgresql | Postgresql | 8.4.1 (including) | 8.4.1 (including) |
Red Hat Enterprise Linux 3 | RedHat | rh-postgresql-0:7.3.21-3 | * |
Red Hat Enterprise Linux 4 | RedHat | postgresql-0:7.4.29-1.el4_8.1 | * |
Red Hat Enterprise Linux 5 | RedHat | postgresql-0:8.1.21-1.el5_5.1 | * |
Postgresql-7.4 | Ubuntu | dapper | * |
Postgresql-8.0 | Ubuntu | dapper | * |
Postgresql-8.1 | Ubuntu | dapper | * |
Postgresql-8.2 | Ubuntu | hardy | * |
Postgresql-8.3 | Ubuntu | hardy | * |
Postgresql-8.3 | Ubuntu | intrepid | * |
Postgresql-8.3 | Ubuntu | jaunty | * |
Postgresql-8.3 | Ubuntu | karmic | * |
Postgresql-8.4 | Ubuntu | karmic | * |