CVE Vulnerabilities

CVE-2010-3781

Published: Oct 06, 2010 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The PL/php add-on 1.4 and earlier for PostgreSQL does not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, a related issue to CVE-2010-3433.

Affected Software

Name Vendor Start Version End Version
Pl/php Alvaro_herrera * 1.4 (including)
Pl/php Alvaro_herrera 1.0 (including) 1.0 (including)
Pl/php Alvaro_herrera 1.1 (including) 1.1 (including)
Pl/php Alvaro_herrera 1.2 (including) 1.2 (including)
Pl/php Alvaro_herrera 1.3.1 (including) 1.3.1 (including)
Pl/php Alvaro_herrera 1.3.2 (including) 1.3.2 (including)
Pl/php Alvaro_herrera 1.3.3 (including) 1.3.3 (including)
Pl/php Alvaro_herrera 1.3.5-beta1 (including) 1.3.5-beta1 (including)

References