CVE Vulnerabilities

CVE-2010-1975

Published: May 19, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove arbitrary parameter settings via a (1) ALTER USER or (2) ALTER DATABASE statement.

Affected Software

NameVendorStart VersionEnd Version
PostgresqlPostgresql7.4 (including)7.4 (including)
PostgresqlPostgresql7.4.1 (including)7.4.1 (including)
PostgresqlPostgresql7.4.2 (including)7.4.2 (including)
PostgresqlPostgresql7.4.3 (including)7.4.3 (including)
PostgresqlPostgresql7.4.4 (including)7.4.4 (including)
PostgresqlPostgresql7.4.5 (including)7.4.5 (including)
PostgresqlPostgresql7.4.6 (including)7.4.6 (including)
PostgresqlPostgresql7.4.7 (including)7.4.7 (including)
PostgresqlPostgresql7.4.8 (including)7.4.8 (including)
PostgresqlPostgresql7.4.9 (including)7.4.9 (including)
PostgresqlPostgresql7.4.10 (including)7.4.10 (including)
PostgresqlPostgresql7.4.11 (including)7.4.11 (including)
PostgresqlPostgresql7.4.12 (including)7.4.12 (including)
PostgresqlPostgresql7.4.13 (including)7.4.13 (including)
PostgresqlPostgresql7.4.14 (including)7.4.14 (including)
PostgresqlPostgresql7.4.15 (including)7.4.15 (including)
PostgresqlPostgresql7.4.16 (including)7.4.16 (including)
PostgresqlPostgresql7.4.17 (including)7.4.17 (including)
PostgresqlPostgresql7.4.18 (including)7.4.18 (including)
PostgresqlPostgresql7.4.19 (including)7.4.19 (including)
PostgresqlPostgresql7.4.20 (including)7.4.20 (including)
PostgresqlPostgresql7.4.21 (including)7.4.21 (including)
PostgresqlPostgresql7.4.22 (including)7.4.22 (including)
PostgresqlPostgresql7.4.23 (including)7.4.23 (including)
PostgresqlPostgresql7.4.24 (including)7.4.24 (including)
PostgresqlPostgresql7.4.25 (including)7.4.25 (including)
PostgresqlPostgresql7.4.26 (including)7.4.26 (including)
PostgresqlPostgresql7.4.27 (including)7.4.27 (including)
PostgresqlPostgresql7.4.28 (including)7.4.28 (including)
Postgresql-7.4Ubuntudapper*
Postgresql-8.0Ubuntudapper*
Postgresql-8.1Ubuntudapper*
Postgresql-8.1Ubuntuupstream*
Postgresql-8.2Ubuntuhardy*
Postgresql-8.3Ubuntuhardy*
Postgresql-8.3Ubuntujaunty*
Postgresql-8.3Ubuntukarmic*
Postgresql-8.3Ubuntuupstream*
Postgresql-8.4Ubuntudevel*
Postgresql-8.4Ubuntukarmic*
Postgresql-8.4Ubuntulucid*
Postgresql-8.4Ubuntumaverick*
Postgresql-8.4Ubuntunatty*
Postgresql-8.4Ubuntuupstream*

References