Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-0866

Опубликовано: 27 фев. 2012
Источник: redhat
CVSS2: 5.2
EPSS Низкий

Описание

CREATE TRIGGER in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 does not properly check the execute permission for trigger functions marked SECURITY DEFINER, which allows remote authenticated users to execute otherwise restricted triggers on arbitrary data by installing the trigger on an attacker-owned table.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4postgresqlWill not fix
Red Hat Enterprise Linux 5postgresqlFixedRHSA-2012:067721.05.2012
Red Hat Enterprise Linux 5postgresql84FixedRHSA-2012:067821.05.2012
Red Hat Enterprise Linux 6postgresqlFixedRHSA-2012:067821.05.2012

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=797222postgresql: Absent permission checks on trigger function to be called when creating a trigger

EPSS

Процентиль: 77%
0.01064
Низкий

5.2 Medium

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

CREATE TRIGGER in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 does not properly check the execute permission for trigger functions marked SECURITY DEFINER, which allows remote authenticated users to execute otherwise restricted triggers on arbitrary data by installing the trigger on an attacker-owned table.

nvd
около 13 лет назад

CREATE TRIGGER in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 does not properly check the execute permission for trigger functions marked SECURITY DEFINER, which allows remote authenticated users to execute otherwise restricted triggers on arbitrary data by installing the trigger on an attacker-owned table.

debian
около 13 лет назад

CREATE TRIGGER in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, ...

github
около 3 лет назад

CREATE TRIGGER in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 does not properly check the execute permission for trigger functions marked SECURITY DEFINER, which allows remote authenticated users to execute otherwise restricted triggers on arbitrary data by installing the trigger on an attacker-owned table.

oracle-oval
около 13 лет назад

ELSA-2012-0677: postgresql security update (MODERATE)

EPSS

Процентиль: 77%
0.01064
Низкий

5.2 Medium

CVSS2