CVE-2014-0067
Published: 31 March 2014
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.
Priority
Status
Package | Release | Status |
---|---|---|
postgresql-8.4 Launchpad, Ubuntu, Debian |
lucid |
Released
(8.4.22-0ubuntu0.10.04)
|
precise |
Released
(8.4.22-0ubuntu0.12.04)
|
|
quantal |
Does not exist
|
|
saucy |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Released
(8.4.22)
|
|
utopic |
Does not exist
|
|
postgresql-9.1 Launchpad, Ubuntu, Debian |
lucid |
Does not exist
|
precise |
Released
(9.1.14-0ubuntu0.12.04)
|
|
quantal |
Ignored
(end of life)
|
|
saucy |
Ignored
(end of life)
|
|
trusty |
Released
(9.1.15-0ubuntu0.14.04)
|
|
upstream |
Released
(9.1.14)
|
|
utopic |
Does not exist
|
|
postgresql-9.3 Launchpad, Ubuntu, Debian |
lucid |
Does not exist
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
saucy |
Does not exist
|
|
trusty |
Released
(9.3.5-0ubuntu0.14.04.1)
|
|
upstream |
Released
(9.3.5)
|
|
utopic |
Does not exist
|