CVE Vulnerabilities

CVE-2013-1901

Published: Apr 04, 2013 | Modified: Dec 01, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) pg_start_backup or (2) pg_stop_backup functions.

Affected Software

Name Vendor Start Version End Version
Postgresql Postgresql 9.2 (including) 9.2 (including)
Postgresql Postgresql 9.2.1 (including) 9.2.1 (including)
Postgresql Postgresql 9.2.2 (including) 9.2.2 (including)
Postgresql Postgresql 9.2.3 (including) 9.2.3 (including)

References