PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10927 | signature vdb entry |
http://www.mandriva.com/security/advisories?name=MDKSA-2005:040 | vendor advisory |
http://marc.info/?l=bugtraq&m=110806034116082&w=2 | mailing list |
http://www.redhat.com/support/errata/RHSA-2005-138.html | patch vendor advisory |
http://archives.postgresql.org/pgsql-hackers/2005-01/msg00922.php | vendor advisory mailing list |
http://secunia.com/advisories/12948 | patch vendor advisory third party advisory |
http://www.securityfocus.com/bid/12417 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/19184 | vdb entry |
http://www.novell.com/linux/security/advisories/2005_36_sudo.html | vendor advisory |