CVE Vulnerabilities

CVE-2016-0766

Published: Feb 17, 2016 | Modified: Jan 19, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privileges via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Postgresql Postgresql 9.1.0 (including) 9.1.20 (excluding)
Postgresql Postgresql 9.2 (including) 9.2.15 (excluding)
Postgresql Postgresql 9.3 (including) 9.3.11 (excluding)
Postgresql Postgresql 9.4 (including) 9.4.6 (excluding)
Postgresql Postgresql 9.5 (including) 9.5 (including)
Postgresql-8.4 Ubuntu precise *
Postgresql-9.1 Ubuntu precise *
Postgresql-9.1 Ubuntu trusty *
Postgresql-9.3 Ubuntu trusty *
Postgresql-9.3 Ubuntu upstream *
Postgresql-9.4 Ubuntu vivid *
Postgresql-9.4 Ubuntu wily *
Postgresql-9.5 Ubuntu upstream *

References