CVE-2007-6600
Summary
| CVE | CVE-2007-6600 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-01-09 21:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21 uses superuser privileges instead of table owner privileges for (1) VACUUM and (2) ANALYZE operations within index functions, and supports (3) SET ROLE and (4) SET SESSION AUTHORIZATION within index functions, which allows remote authenticated users to gain privileges. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Postgresql | Postgresql | 7.3 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.1 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.10 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.11 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.12 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.13 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.14 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.15 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.16 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.17 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.18 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.19 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.2 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.3 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.4 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.5 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.6 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.7 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.8 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.9 | All | All | All |
| Application | Postgresql | Postgresql | 7.4 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.1 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.10 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.11 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.12 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.13 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.14 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.16 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.17 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.18 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.2 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.3 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.4 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.5 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.6 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.7 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.8 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.0 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.0 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.11 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.12 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.13 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.14 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Gentoo Linux Documentation -- PostgreSQL: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Support / Security / Advisories / / MDVSA-2008:004 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SUSE update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| USN-568-1: PostgreSQL vulnerabilities | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | |
| SecurityTracker.com Archives - PostgreSQL Bugs Let Remote Authenticated Users Deny Service and Obtain Elevated Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Mandriva update for postgresql - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Fedora update for postgresql - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian update for postgresql-7.4 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| PostgreSQL Multiple Privilege Escalation and Denial of Service Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| HP Internet Express for Tru64 UNIX Multiple PostgreSQL Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| PostgreSQL Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [SECURITY] Fedora 8 Update: postgresql-8.2.6-1.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| rPath update for postgresql and postgresql-server - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian -- Security Information -- DSA-1460-1 postgresql-8.1 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Red Hat update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| issues.rpath.com/browse/RPL-1768 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| [security-announce] SUSE Security Announcement: PostgreSQL security issu | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | |
| Sun Solaris 10 PostgreSQL Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Support | Red Hat | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Red Hat update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Ubuntu update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Debian update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [SECURITY] Fedora 7 Update: postgresql-8.2.6-1.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| PostgreSQL: News: 2008-01-07 Cumulative Security Update Release | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Patch, Vendor Advisory |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| Gentoo update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian -- Security Information -- DSA-1463-1 postgresql-7.4 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.