Lucene search

K
redhatRedHatRHSA-2009:1485
HistoryOct 07, 2009 - 12:00 a.m.

(RHSA-2009:1485) Moderate: postgresql security update

2009-10-0700:00:00
access.redhat.com
33

0.005 Low

EPSS

Percentile

77.1%

PostgreSQL is an advanced object-relational database management system
(DBMS).

It was discovered that the upstream patch for CVE-2007-6600 included in the
Red Hat Security Advisory RHSA-2008:0039 did not include protection against
misuse of the RESET ROLE and RESET SESSION AUTHORIZATION commands. An
authenticated user could use this flaw to install malicious code that would
later execute with superuser privileges. (CVE-2009-3230)

All PostgreSQL users should upgrade to these updated packages, which
contain a backported patch to correct this issue. If you are running a
PostgreSQL server, the postgresql service must be restarted for this update
to take effect.