CVE Vulnerabilities

CVE-2014-0067

Published: Mar 31, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
4.6 LOW
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The make check command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.

Affected Software

NameVendorStart VersionEnd Version
Mac_os_xApple10.10.4 (including)10.10.4 (including)
Mac_os_x_serverApple5.0.3 (including)5.0.3 (including)
Postgresql-8.4Ubuntulucid*
Postgresql-8.4Ubuntuprecise*
Postgresql-8.4Ubuntuupstream*
Postgresql-9.1Ubuntuprecise*
Postgresql-9.1Ubuntuquantal*
Postgresql-9.1Ubuntusaucy*
Postgresql-9.1Ubuntutrusty*
Postgresql-9.1Ubuntuupstream*
Postgresql-9.3Ubuntuesm-infra-legacy/trusty*
Postgresql-9.3Ubuntutrusty*
Postgresql-9.3Ubuntutrusty/esm*
Postgresql-9.3Ubuntuupstream*

References