CVE-2009-3230
Summary
| CVE | CVE-2009-3230 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-09-17 10:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7.4.26 does not use the appropriate privileges for the (1) RESET ROLE and (2) RESET SESSION AUTHORIZATION operations, which allows remote authenticated users to gain privileges. NOTE: this is due to an incomplete fix for CVE-2007-6600. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Postgresql | Postgresql | 7.4 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.1 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.10 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.11 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.12 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.13 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.14 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.15 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.16 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.17 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.18 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.19 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.2 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.20 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.21 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.22 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.23 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.24 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.25 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.3 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.4 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.5 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.6 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.7 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.8 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.0 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.11 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.12 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.13 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.14 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.15 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.16 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.17 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.18 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.19 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.20 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.21 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.11 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.12 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.13 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.14 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.15 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.16 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.10 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.11 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.12 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.13 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.6 | All | All | All |
| Application | Postgresql | Postgresql | 8.3.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 10 Update: postgresql-8.3.8-1.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:017 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| '[security bulletin] HPSBMU02781 SSRT100617 rev.1 - HP Network Node Manager i (NNMi) for HP-UX, Linux' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Debian update for postgresql - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| PostgreSQL Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| USN-834-1: PostgreSQL vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| [SECURITY] Fedora 11 Update: postgresql-8.3.8-1.fc11 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| PostgreSQL: Documentation: Manuals: PostgreSQL 8.3: Release 8.3.8 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Vendor Advisory |
| Fedora update for postgresql - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Re: Incorrect CVE reference on security page | af854a3a-2127-422b-91ae-364da2661108 | archives.postgresql.org | |
| wiki.rpath.com/wiki/Advisories:rPSA-2010-0012 | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | |
| PostgreSQL "RESET SESSION AUTHORIZATION" Privilege Escalation - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| PostgreSQL: Security Information | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Vendor Advisory |
| Security Advisory SA36800 - Ubuntu update for postgresql - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Bug 522085 – CVE-2009-3230 postgresql: SQL privilege escalation, incomplete fix for CVE-2007-6600 | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| PostgreSQL Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian -- Security Information -- DSA-1900-1 postgresql-7.4, postgresql-8.1, postgresql-8.3, postgresql-8.4 | af854a3a-2127-422b-91ae-364da2661108 | www.us.debian.org | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:016 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.