Lucene search

K
postgresqlPostgreSQL Global Development GroupPOSTGRESQL:CVE-2007-6600
HistoryJan 09, 2008 - 9:46 p.m.

Vulnerability in core server (CVE-2007-6600)

2008-01-0921:46:00
PostgreSQL Global Development Group
www.postgresql.org
46

0.005 Low

EPSS

Percentile

77.1%

Two vulnerabilities in how ANALYZE executes user defined functions that are part of expression indexes allows users to gain superuser privileges. A valid login that has permissions to create functions and tables is required to exploit this vulnearbility.