The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-0019-1 | postgresql-8.4 update |
Debian DSA |
DSA-2864-1 | postgresql-8.4 security update |
Debian DSA |
DSA-2865-1 | postgresql-9.1 security update |
EUVD |
EUVD-2014-0160 | The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T09:05:38.915Z
Reserved: 2013-12-03T00:00:00.000Z
Link: CVE-2014-0067
No data.
Status : Deferred
Published: 2014-03-31T14:58:15.787
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-0067
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD