First published: Fri Mar 28 2014(Updated: )
The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to gain privileges via a function that is (1) defined in another language or (2) not allowed to be directly called by the user due to permissions.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
PostgreSQL Common | <=8.4.19 | |
PostgreSQL Common | =8.4.1 | |
PostgreSQL Common | =8.4.2 | |
PostgreSQL Common | =8.4.3 | |
PostgreSQL Common | =8.4.4 | |
PostgreSQL Common | =8.4.5 | |
PostgreSQL Common | =8.4.6 | |
PostgreSQL Common | =8.4.7 | |
PostgreSQL Common | =8.4.8 | |
PostgreSQL Common | =8.4.9 | |
PostgreSQL Common | =8.4.10 | |
PostgreSQL Common | =8.4.11 | |
PostgreSQL Common | =8.4.12 | |
PostgreSQL Common | =8.4.13 | |
PostgreSQL Common | =8.4.14 | |
PostgreSQL Common | =8.4.15 | |
PostgreSQL Common | =8.4.16 | |
PostgreSQL Common | =8.4.17 | |
PostgreSQL Common | =8.4.18 | |
PostgreSQL Common | =9.0 | |
PostgreSQL Common | =9.0.1 | |
PostgreSQL Common | =9.0.2 | |
PostgreSQL Common | =9.0.3 | |
PostgreSQL Common | =9.0.4 | |
PostgreSQL Common | =9.0.5 | |
PostgreSQL Common | =9.0.6 | |
PostgreSQL Common | =9.0.7 | |
PostgreSQL Common | =9.0.8 | |
PostgreSQL Common | =9.0.9 | |
PostgreSQL Common | =9.0.10 | |
PostgreSQL Common | =9.0.11 | |
PostgreSQL Common | =9.0.12 | |
PostgreSQL Common | =9.0.13 | |
PostgreSQL Common | =9.0.14 | |
PostgreSQL Common | =9.0.15 | |
PostgreSQL Common | =9.1 | |
PostgreSQL Common | =9.1.1 | |
PostgreSQL Common | =9.1.2 | |
PostgreSQL Common | =9.1.3 | |
PostgreSQL Common | =9.1.4 | |
PostgreSQL Common | =9.1.5 | |
PostgreSQL Common | =9.1.6 | |
PostgreSQL Common | =9.1.7 | |
PostgreSQL Common | =9.1.8 | |
PostgreSQL Common | =9.1.9 | |
PostgreSQL Common | =9.1.10 | |
PostgreSQL Common | =9.1.11 | |
PostgreSQL Common | =9.2 | |
PostgreSQL Common | =9.2.1 | |
PostgreSQL Common | =9.2.2 | |
PostgreSQL Common | =9.2.3 | |
PostgreSQL Common | =9.2.4 | |
PostgreSQL Common | =9.2.5 | |
PostgreSQL Common | =9.2.6 | |
PostgreSQL Common | =9.3 | |
PostgreSQL Common | =9.3.1 | |
PostgreSQL Common | =9.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0061 is considered a medium severity vulnerability that allows privilege escalation for remote authenticated users.
To fix CVE-2014-0061, upgrade your PostgreSQL installation to the latest version or apply the security patches provided by the vendor.
CVE-2014-0061 affects PostgreSQL versions before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3.
CVE-2014-0061 allows remote authenticated users to gain elevated privileges by exploiting improperly validated function definitions.
Yes, CVE-2014-0061 requires that attackers have authenticated access to the PostgreSQL database to exploit the vulnerability.