First published: Fri Oct 01 2010(Updated: )
A flaw was found in the way PostgreSQL handled SQL functions, created with SECURITY DEFINER keyword and implemented in PL/Perl or PL/Tcl languages. Once the PL/Perl or PL/Tcl procedural language was registered on particular database, a remote, authenticated user, running a specially-crafted PL/Perl or PL/Tcl script could use this flaw to bypass intended PostgreSQL SECURITY DEFINER function definition refinement / protection mechanism, allowing them to run particular PostgreSQL function under their effective user ID, potentially leading to escalation of their privileges. References: [1] <a href="http://www.postgresql.org/docs/8.1/interactive/plperl.html">http://www.postgresql.org/docs/8.1/interactive/plperl.html</a> [2] <a href="http://www.postgresql.org/docs/8.1/static/pltcl.html">http://www.postgresql.org/docs/8.1/static/pltcl.html</a> [3] <a href="http://www.postgresql.org/docs/8.1/interactive/sql-createfunction.html">http://www.postgresql.org/docs/8.1/interactive/sql-createfunction.html</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
PostgreSQL PostgreSQL | =7.4 | |
PostgreSQL PostgreSQL | =7.4.1 | |
PostgreSQL PostgreSQL | =7.4.2 | |
PostgreSQL PostgreSQL | =7.4.3 | |
PostgreSQL PostgreSQL | =7.4.4 | |
PostgreSQL PostgreSQL | =7.4.5 | |
PostgreSQL PostgreSQL | =7.4.6 | |
PostgreSQL PostgreSQL | =7.4.7 | |
PostgreSQL PostgreSQL | =7.4.8 | |
PostgreSQL PostgreSQL | =7.4.9 | |
PostgreSQL PostgreSQL | =7.4.10 | |
PostgreSQL PostgreSQL | =7.4.11 | |
PostgreSQL PostgreSQL | =7.4.12 | |
PostgreSQL PostgreSQL | =7.4.13 | |
PostgreSQL PostgreSQL | =7.4.14 | |
PostgreSQL PostgreSQL | =7.4.15 | |
PostgreSQL PostgreSQL | =7.4.16 | |
PostgreSQL PostgreSQL | =7.4.17 | |
PostgreSQL PostgreSQL | =7.4.18 | |
PostgreSQL PostgreSQL | =7.4.19 | |
PostgreSQL PostgreSQL | =7.4.20 | |
PostgreSQL PostgreSQL | =7.4.21 | |
PostgreSQL PostgreSQL | =7.4.22 | |
PostgreSQL PostgreSQL | =7.4.23 | |
PostgreSQL PostgreSQL | =7.4.24 | |
PostgreSQL PostgreSQL | =7.4.25 | |
PostgreSQL PostgreSQL | =7.4.26 | |
PostgreSQL PostgreSQL | =7.4.27 | |
PostgreSQL PostgreSQL | =7.4.28 | |
PostgreSQL PostgreSQL | =7.4.29 | |
PostgreSQL PostgreSQL | =8.0 | |
PostgreSQL PostgreSQL | =8.0.1 | |
PostgreSQL PostgreSQL | =8.0.2 | |
PostgreSQL PostgreSQL | =8.0.3 | |
PostgreSQL PostgreSQL | =8.0.4 | |
PostgreSQL PostgreSQL | =8.0.5 | |
PostgreSQL PostgreSQL | =8.0.6 | |
PostgreSQL PostgreSQL | =8.0.7 | |
PostgreSQL PostgreSQL | =8.0.8 | |
PostgreSQL PostgreSQL | =8.0.9 | |
PostgreSQL PostgreSQL | =8.0.10 | |
PostgreSQL PostgreSQL | =8.0.11 | |
PostgreSQL PostgreSQL | =8.0.12 | |
PostgreSQL PostgreSQL | =8.0.13 | |
PostgreSQL PostgreSQL | =8.0.14 | |
PostgreSQL PostgreSQL | =8.0.15 | |
PostgreSQL PostgreSQL | =8.0.16 | |
PostgreSQL PostgreSQL | =8.0.17 | |
PostgreSQL PostgreSQL | =8.0.18 | |
PostgreSQL PostgreSQL | =8.0.19 | |
PostgreSQL PostgreSQL | =8.0.20 | |
PostgreSQL PostgreSQL | =8.0.21 | |
PostgreSQL PostgreSQL | =8.0.22 | |
PostgreSQL PostgreSQL | =8.0.23 | |
PostgreSQL PostgreSQL | =8.0.24 | |
PostgreSQL PostgreSQL | =8.0.25 | |
PostgreSQL PostgreSQL | =8.1 | |
PostgreSQL PostgreSQL | =8.1.1 | |
PostgreSQL PostgreSQL | =8.1.2 | |
PostgreSQL PostgreSQL | =8.1.3 | |
PostgreSQL PostgreSQL | =8.1.4 | |
PostgreSQL PostgreSQL | =8.1.5 | |
PostgreSQL PostgreSQL | =8.1.6 | |
PostgreSQL PostgreSQL | =8.1.7 | |
PostgreSQL PostgreSQL | =8.1.8 | |
PostgreSQL PostgreSQL | =8.1.9 | |
PostgreSQL PostgreSQL | =8.1.10 | |
PostgreSQL PostgreSQL | =8.1.11 | |
PostgreSQL PostgreSQL | =8.1.12 | |
PostgreSQL PostgreSQL | =8.1.13 | |
PostgreSQL PostgreSQL | =8.1.14 | |
PostgreSQL PostgreSQL | =8.1.15 | |
PostgreSQL PostgreSQL | =8.1.16 | |
PostgreSQL PostgreSQL | =8.1.17 | |
PostgreSQL PostgreSQL | =8.1.18 | |
PostgreSQL PostgreSQL | =8.1.19 | |
PostgreSQL PostgreSQL | =8.1.20 | |
PostgreSQL PostgreSQL | =8.1.21 | |
PostgreSQL PostgreSQL | =8.2 | |
PostgreSQL PostgreSQL | =8.2.1 | |
PostgreSQL PostgreSQL | =8.2.2 | |
PostgreSQL PostgreSQL | =8.2.3 | |
PostgreSQL PostgreSQL | =8.2.4 | |
PostgreSQL PostgreSQL | =8.2.5 | |
PostgreSQL PostgreSQL | =8.2.6 | |
PostgreSQL PostgreSQL | =8.2.7 | |
PostgreSQL PostgreSQL | =8.2.8 | |
PostgreSQL PostgreSQL | =8.2.9 | |
PostgreSQL PostgreSQL | =8.2.10 | |
PostgreSQL PostgreSQL | =8.2.11 | |
PostgreSQL PostgreSQL | =8.2.12 | |
PostgreSQL PostgreSQL | =8.2.13 | |
PostgreSQL PostgreSQL | =8.2.14 | |
PostgreSQL PostgreSQL | =8.2.15 | |
PostgreSQL PostgreSQL | =8.2.16 | |
PostgreSQL PostgreSQL | =8.2.17 | |
PostgreSQL PostgreSQL | =8.3 | |
PostgreSQL PostgreSQL | =8.3.1 | |
PostgreSQL PostgreSQL | =8.3.2 | |
PostgreSQL PostgreSQL | =8.3.3 | |
PostgreSQL PostgreSQL | =8.3.4 | |
PostgreSQL PostgreSQL | =8.3.5 | |
PostgreSQL PostgreSQL | =8.3.6 | |
PostgreSQL PostgreSQL | =8.3.7 | |
PostgreSQL PostgreSQL | =8.3.8 | |
PostgreSQL PostgreSQL | =8.3.9 | |
PostgreSQL PostgreSQL | =8.3.10 | |
PostgreSQL PostgreSQL | =8.3.11 | |
PostgreSQL PostgreSQL | =8.4 | |
PostgreSQL PostgreSQL | =8.4.1 | |
PostgreSQL PostgreSQL | =8.4.2 | |
PostgreSQL PostgreSQL | =8.4.3 | |
PostgreSQL PostgreSQL | =8.4.4 | |
PostgreSQL PostgreSQL | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.