CVE-2014-0067
Publication date 31 March 2014
Last updated 24 July 2024
Ubuntu priority
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.
Status
Package | Ubuntu Release | Status |
---|---|---|
postgresql-8.4 | ||
14.04 LTS trusty | Not in release | |
postgresql-9.1 | ||
14.04 LTS trusty |
Fixed 9.1.15-0ubuntu0.14.04
|
|
postgresql-9.3 | ||
14.04 LTS trusty |
Fixed 9.3.5-0ubuntu0.14.04.1
|
|