CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:S/C:P/I:P/A:P
EPSS
Percentile
73.3%
Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x
before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before
8.2.4 allows remote authenticated users, when permitted to call a SECURITY
DEFINER function, to gain the privileges of the function owner, related to
“search_path settings.”
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 6.06 | noarch | postgresql-8.1 | < 8.1.9-0ubuntu0.6.06 | UNKNOWN |
ubuntu | 6.10 | noarch | postgresql-8.1 | < 8.1.9-0ubuntu0.6.10 | UNKNOWN |
ubuntu | 7.10 | noarch | postgresql-8.1 | < 8.1.10-1 | UNKNOWN |
ubuntu | 7.04 | noarch | postgresql-8.2 | < 8.2.4-0ubuntu0.7.04 | UNKNOWN |
ubuntu | 7.10 | noarch | postgresql-8.2 | < 8.2.5-1 | UNKNOWN |
ubuntu | 8.04 | noarch | postgresql-8.2 | < 8.2.5-1 | UNKNOWN |