The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to gain privileges via a function that is (1) defined in another language or (2) not allowed to be directly called by the user due to permissions.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2864-1 | postgresql-8.4 security update |
Debian DSA |
DSA-2865-1 | postgresql-9.1 security update |
EUVD |
EUVD-2014-0154 | The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to gain privileges via a function that is (1) defined in another language or (2) not allowed to be directly called by the user due to permissions. |
Ubuntu USN |
USN-2120-1 | PostgreSQL vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T09:05:38.995Z
Reserved: 2013-12-03T00:00:00
Link: CVE-2014-0061
No data.
Status : Deferred
Published: 2014-03-31T14:58:15.383
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-0061
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN