CVE-2014-0067: Medium severity Apple iOS and macOS vulnerability
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0067?
CVE-2014-0067 has a severity level that allows local users to gain higher privileges on the affected systems.
How do I fix CVE-2014-0067?
To mitigate CVE-2014-0067, ensure you upgrade PostgreSQL to a version later than 9.3.3.
Which systems are affected by CVE-2014-0067?
CVE-2014-0067 affects PostgreSQL versions 9.3.3 and earlier, along with various OS versions like macOS Yosemite and Apple Mac OS X Server.
What type of vulnerability is CVE-2014-0067?
CVE-2014-0067 is a local privilege escalation vulnerability due to improper configuration during test suite setups.
Can I be attacked through CVE-2014-0067 if my PostgreSQL version is up to date?
If you are using a version of PostgreSQL later than 9.3.3, you are not vulnerable to CVE-2014-0067.