CVE Vulnerabilities

CVE-2016-0766

Published: Feb 17, 2016 | Modified: Apr 12, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privileges via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
PostgresqlPostgresql9.1.0 (including)9.1.20 (excluding)
PostgresqlPostgresql9.2 (including)9.2.15 (excluding)
PostgresqlPostgresql9.3 (including)9.3.11 (excluding)
PostgresqlPostgresql9.4 (including)9.4.6 (excluding)
PostgresqlPostgresql9.5 (including)9.5 (including)
Postgresql-8.4Ubuntuprecise*
Postgresql-9.1Ubuntuprecise*
Postgresql-9.1Ubuntutrusty*
Postgresql-9.3Ubuntuesm-infra-legacy/trusty*
Postgresql-9.3Ubuntutrusty*
Postgresql-9.3Ubuntutrusty/esm*
Postgresql-9.3Ubuntuupstream*
Postgresql-9.4Ubuntuvivid*
Postgresql-9.4Ubuntuwily*
Postgresql-9.5Ubuntuupstream*

References