PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove arbitrary parameter settings via a (1) ALTER USER or (2) ALTER DATABASE statement.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
History
21 Nov 2024, 01:15
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html - | |
References | () http://marc.info/?l=bugtraq&m=134124585221119&w=2 - | |
References | () http://secunia.com/advisories/39939 - | |
References | () http://www.debian.org/security/2010/dsa-2051 - | |
References | () http://www.mandriva.com/security/advisories?name=MDVSA-2010:103 - | |
References | () http://www.postgresql.org/docs/current/static/release-7-4-29.html - | |
References | () http://www.postgresql.org/docs/current/static/release-8-0-25.html - | |
References | () http://www.postgresql.org/docs/current/static/release-8-1-21.html - | |
References | () http://www.postgresql.org/docs/current/static/release-8-2-17.html - | |
References | () http://www.postgresql.org/docs/current/static/release-8-3-11.html - | |
References | () http://www.postgresql.org/docs/current/static/release-8-4-4.html - | |
References | () http://www.securityfocus.com/bid/40304 - | |
References | () http://www.vupen.com/english/advisories/2010/1207 - | |
References | () http://www.vupen.com/english/advisories/2010/1221 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11004 - |
Information
Published : 2010-05-19 18:30
Updated : 2024-11-21 01:15
NVD link : CVE-2010-1975
Mitre link : CVE-2010-1975
CVE.ORG link : CVE-2010-1975
JSON object : View
Products Affected
postgresql
- postgresql
CWE
CWE-264
Permissions, Privileges, and Access Controls