CVE Vulnerabilities

CVE-2014-0061

Published: Mar 31, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
6.5 MODERATE
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to gain privileges via a function that is (1) defined in another language or (2) not allowed to be directly called by the user due to permissions.

Affected Software

NameVendorStart VersionEnd Version
PostgresqlPostgresql*8.4.19 (including)
PostgresqlPostgresql8.4.1 (including)8.4.1 (including)
PostgresqlPostgresql8.4.2 (including)8.4.2 (including)
PostgresqlPostgresql8.4.3 (including)8.4.3 (including)
PostgresqlPostgresql8.4.4 (including)8.4.4 (including)
PostgresqlPostgresql8.4.5 (including)8.4.5 (including)
PostgresqlPostgresql8.4.6 (including)8.4.6 (including)
PostgresqlPostgresql8.4.7 (including)8.4.7 (including)
PostgresqlPostgresql8.4.8 (including)8.4.8 (including)
PostgresqlPostgresql8.4.9 (including)8.4.9 (including)
PostgresqlPostgresql8.4.10 (including)8.4.10 (including)
PostgresqlPostgresql8.4.11 (including)8.4.11 (including)
PostgresqlPostgresql8.4.12 (including)8.4.12 (including)
PostgresqlPostgresql8.4.13 (including)8.4.13 (including)
PostgresqlPostgresql8.4.14 (including)8.4.14 (including)
PostgresqlPostgresql8.4.15 (including)8.4.15 (including)
PostgresqlPostgresql8.4.16 (including)8.4.16 (including)
PostgresqlPostgresql8.4.17 (including)8.4.17 (including)
PostgresqlPostgresql8.4.18 (including)8.4.18 (including)
PostgresqlPostgresql9.0 (including)9.0 (including)
PostgresqlPostgresql9.0.1 (including)9.0.1 (including)
PostgresqlPostgresql9.0.2 (including)9.0.2 (including)
PostgresqlPostgresql9.0.3 (including)9.0.3 (including)
PostgresqlPostgresql9.0.4 (including)9.0.4 (including)
PostgresqlPostgresql9.0.5 (including)9.0.5 (including)
PostgresqlPostgresql9.0.6 (including)9.0.6 (including)
PostgresqlPostgresql9.0.7 (including)9.0.7 (including)
PostgresqlPostgresql9.0.8 (including)9.0.8 (including)
PostgresqlPostgresql9.0.9 (including)9.0.9 (including)
PostgresqlPostgresql9.0.10 (including)9.0.10 (including)
PostgresqlPostgresql9.0.11 (including)9.0.11 (including)
PostgresqlPostgresql9.0.12 (including)9.0.12 (including)
PostgresqlPostgresql9.0.13 (including)9.0.13 (including)
PostgresqlPostgresql9.0.14 (including)9.0.14 (including)
PostgresqlPostgresql9.0.15 (including)9.0.15 (including)
PostgresqlPostgresql9.1 (including)9.1 (including)
PostgresqlPostgresql9.1.1 (including)9.1.1 (including)
PostgresqlPostgresql9.1.2 (including)9.1.2 (including)
PostgresqlPostgresql9.1.3 (including)9.1.3 (including)
PostgresqlPostgresql9.1.4 (including)9.1.4 (including)
PostgresqlPostgresql9.1.5 (including)9.1.5 (including)
PostgresqlPostgresql9.1.6 (including)9.1.6 (including)
PostgresqlPostgresql9.1.7 (including)9.1.7 (including)
PostgresqlPostgresql9.1.8 (including)9.1.8 (including)
PostgresqlPostgresql9.1.9 (including)9.1.9 (including)
PostgresqlPostgresql9.1.10 (including)9.1.10 (including)
PostgresqlPostgresql9.1.11 (including)9.1.11 (including)
PostgresqlPostgresql9.2 (including)9.2 (including)
PostgresqlPostgresql9.2.1 (including)9.2.1 (including)
PostgresqlPostgresql9.2.2 (including)9.2.2 (including)
PostgresqlPostgresql9.2.3 (including)9.2.3 (including)
PostgresqlPostgresql9.2.4 (including)9.2.4 (including)
PostgresqlPostgresql9.2.5 (including)9.2.5 (including)
PostgresqlPostgresql9.2.6 (including)9.2.6 (including)
PostgresqlPostgresql9.3 (including)9.3 (including)
PostgresqlPostgresql9.3.1 (including)9.3.1 (including)
PostgresqlPostgresql9.3.2 (including)9.3.2 (including)
CloudForms Management Engine 5.xRedHatcfme-0:5.2.3.2-1.el6cf*
CloudForms Management Engine 5.xRedHatpostgresql92-postgresql-0:9.2.7-1.1.el6*
CloudForms Management Engine 5.xRedHatprince-0:9.0r2-4.el6cf*
CloudForms Management Engine 5.xRedHatruby193-rubygem-actionpack-1:3.2.13-6.el6cf*
Red Hat Enterprise Linux 5RedHatpostgresql84-0:8.4.20-1.el5_10*
Red Hat Enterprise Linux 5RedHatpostgresql-0:8.1.23-10.el5_10*
Red Hat Enterprise Linux 6RedHatpostgresql-0:8.4.20-1.el6_5*
Red Hat Software Collections for RHEL-6RedHatpostgresql92-postgresql-0:9.2.7-1.1.el6*
Postgresql-8.4Ubuntulucid*
Postgresql-8.4Ubuntuprecise*
Postgresql-8.4Ubuntuupstream*
Postgresql-9.1Ubuntuprecise*
Postgresql-9.1Ubuntuquantal*
Postgresql-9.1Ubuntusaucy*
Postgresql-9.1Ubuntutrusty*
Postgresql-9.1Ubuntuupstream*
Postgresql-9.3Ubuntuesm-infra-legacy/trusty*
Postgresql-9.3Ubuntutrusty*
Postgresql-9.3Ubuntutrusty/esm*
Postgresql-9.3Ubuntuupstream*

References