The make check command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mac_os_x | Apple | 10.10.4 (including) | 10.10.4 (including) |
Mac_os_x_server | Apple | 5.0.3 (including) | 5.0.3 (including) |
Postgresql-8.4 | Ubuntu | lucid | * |
Postgresql-8.4 | Ubuntu | precise | * |
Postgresql-8.4 | Ubuntu | upstream | * |
Postgresql-9.1 | Ubuntu | precise | * |
Postgresql-9.1 | Ubuntu | quantal | * |
Postgresql-9.1 | Ubuntu | saucy | * |
Postgresql-9.1 | Ubuntu | trusty | * |
Postgresql-9.1 | Ubuntu | upstream | * |
Postgresql-9.3 | Ubuntu | trusty | * |
Postgresql-9.3 | Ubuntu | upstream | * |