CVE Vulnerabilities

CVE-2010-1975

Published: May 19, 2010 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
4.9 LOW
AV:A/AC:M/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW

PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove arbitrary parameter settings via a (1) ALTER USER or (2) ALTER DATABASE statement.

Affected Software

Name Vendor Start Version End Version
Postgresql Postgresql 7.4 (including) 7.4 (including)
Postgresql Postgresql 7.4.1 (including) 7.4.1 (including)
Postgresql Postgresql 7.4.2 (including) 7.4.2 (including)
Postgresql Postgresql 7.4.3 (including) 7.4.3 (including)
Postgresql Postgresql 7.4.4 (including) 7.4.4 (including)
Postgresql Postgresql 7.4.5 (including) 7.4.5 (including)
Postgresql Postgresql 7.4.6 (including) 7.4.6 (including)
Postgresql Postgresql 7.4.7 (including) 7.4.7 (including)
Postgresql Postgresql 7.4.8 (including) 7.4.8 (including)
Postgresql Postgresql 7.4.9 (including) 7.4.9 (including)
Postgresql Postgresql 7.4.10 (including) 7.4.10 (including)
Postgresql Postgresql 7.4.11 (including) 7.4.11 (including)
Postgresql Postgresql 7.4.12 (including) 7.4.12 (including)
Postgresql Postgresql 7.4.13 (including) 7.4.13 (including)
Postgresql Postgresql 7.4.14 (including) 7.4.14 (including)
Postgresql Postgresql 7.4.15 (including) 7.4.15 (including)
Postgresql Postgresql 7.4.16 (including) 7.4.16 (including)
Postgresql Postgresql 7.4.17 (including) 7.4.17 (including)
Postgresql Postgresql 7.4.18 (including) 7.4.18 (including)
Postgresql Postgresql 7.4.19 (including) 7.4.19 (including)
Postgresql Postgresql 7.4.20 (including) 7.4.20 (including)
Postgresql Postgresql 7.4.21 (including) 7.4.21 (including)
Postgresql Postgresql 7.4.22 (including) 7.4.22 (including)
Postgresql Postgresql 7.4.23 (including) 7.4.23 (including)
Postgresql Postgresql 7.4.24 (including) 7.4.24 (including)
Postgresql Postgresql 7.4.25 (including) 7.4.25 (including)
Postgresql Postgresql 7.4.26 (including) 7.4.26 (including)
Postgresql Postgresql 7.4.27 (including) 7.4.27 (including)
Postgresql Postgresql 7.4.28 (including) 7.4.28 (including)
Red Hat Enterprise Linux 4 RedHat postgresql-0:7.4.29-1.el4_8.1 *
Red Hat Enterprise Linux 5 RedHat postgresql-0:8.1.21-1.el5_5.1 *
Red Hat Enterprise Linux 5 RedHat postgresql84-0:8.4.4-1.el5_5.1 *
Postgresql-7.4 Ubuntu dapper *
Postgresql-8.0 Ubuntu dapper *
Postgresql-8.1 Ubuntu dapper *
Postgresql-8.1 Ubuntu upstream *
Postgresql-8.2 Ubuntu hardy *
Postgresql-8.3 Ubuntu hardy *
Postgresql-8.3 Ubuntu jaunty *
Postgresql-8.3 Ubuntu karmic *
Postgresql-8.3 Ubuntu upstream *
Postgresql-8.4 Ubuntu devel *
Postgresql-8.4 Ubuntu karmic *
Postgresql-8.4 Ubuntu lucid *
Postgresql-8.4 Ubuntu maverick *
Postgresql-8.4 Ubuntu natty *
Postgresql-8.4 Ubuntu upstream *

References