PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a (1) " (double quote), (2) \ (backslash), (3) carriage return, or (4) newline character in a (a) database or (b) role name that is mishandled during an administrative operation.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 02:54
Type | Values Removed | Values Added |
---|---|---|
References | () http://rhn.redhat.com/errata/RHSA-2016-1781.html - | |
References | () http://rhn.redhat.com/errata/RHSA-2016-1820.html - | |
References | () http://rhn.redhat.com/errata/RHSA-2016-1821.html - | |
References | () http://rhn.redhat.com/errata/RHSA-2016-2606.html - | |
References | () http://www.debian.org/security/2016/dsa-3646 - Third Party Advisory | |
References | () http://www.securityfocus.com/bid/92435 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1036617 - Third Party Advisory, VDB Entry | |
References | () https://access.redhat.com/errata/RHSA-2017:2425 - | |
References | () https://security.gentoo.org/glsa/201701-33 - | |
References | () https://www.postgresql.org/about/news/1688/ - Patch, Third Party Advisory, VDB Entry | |
References | () https://www.postgresql.org/docs/current/static/release-9-1-23.html - Release Notes, Vendor Advisory | |
References | () https://www.postgresql.org/docs/current/static/release-9-2-18.html - Release Notes, Vendor Advisory | |
References | () https://www.postgresql.org/docs/current/static/release-9-3-14.html - Release Notes, Vendor Advisory | |
References | () https://www.postgresql.org/docs/current/static/release-9-4-9.html - Release Notes, Vendor Advisory | |
References | () https://www.postgresql.org/docs/current/static/release-9-5-4.html - Release Notes, Vendor Advisory |
Information
Published : 2016-12-09 23:59
Updated : 2024-11-21 02:54
NVD link : CVE-2016-5424
Mitre link : CVE-2016-5424
CVE.ORG link : CVE-2016-5424
JSON object : View
Products Affected
debian
- debian_linux
postgresql
- postgresql
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')