CVE-2016-5424
Summary
| CVE | CVE-2016-5424 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-12-09 23:59:02 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a (1) " (double quote), (2) \ (backslash), (3) carriage return, or (4) newline character in a (a) database or (b) role name that is mishandled during an administrative operation. |
Risk And Classification
Primary CVSS: v3.0 7.1 HIGH from [email protected]
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.016740000 probability, percentile 0.822790000 (date 2026-05-10)
Problem Types: CWE-94 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.1 | HIGH | CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 4.6 | AV:N/AC:H/Au:S/C:P/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
LowUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:H/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | Postgresql | Postgresql | 9.2 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.1 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.10 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.11 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.12 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.13 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.14 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.15 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.16 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.17 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.2 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.3 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.4 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.5 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.6 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.7 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.8 | All | All | All |
| Application | Postgresql | Postgresql | 9.2.9 | All | All | All |
| Application | Postgresql | Postgresql | 9.3 | All | All | All |
| Application | Postgresql | Postgresql | 9.3.1 | All | All | All |
| Application | Postgresql | Postgresql | 9.3.10 | All | All | All |
| Application | Postgresql | Postgresql | 9.3.11 | All | All | All |
| Application | Postgresql | Postgresql | 9.3.12 | All | All | All |
| Application | Postgresql | Postgresql | 9.3.13 | All | All | All |
| Application | Postgresql | Postgresql | 9.3.2 | All | All | All |
| Application | Postgresql | Postgresql | 9.3.3 | All | All | All |
| Application | Postgresql | Postgresql | 9.3.4 | All | All | All |
| Application | Postgresql | Postgresql | 9.3.5 | All | All | All |
| Application | Postgresql | Postgresql | 9.3.6 | All | All | All |
| Application | Postgresql | Postgresql | 9.3.7 | All | All | All |
| Application | Postgresql | Postgresql | 9.3.8 | All | All | All |
| Application | Postgresql | Postgresql | 9.3.9 | All | All | All |
| Application | Postgresql | Postgresql | 9.4 | All | All | All |
| Application | Postgresql | Postgresql | 9.4.1 | All | All | All |
| Application | Postgresql | Postgresql | 9.4.2 | All | All | All |
| Application | Postgresql | Postgresql | 9.4.3 | All | All | All |
| Application | Postgresql | Postgresql | 9.4.4 | All | All | All |
| Application | Postgresql | Postgresql | 9.4.5 | All | All | All |
| Application | Postgresql | Postgresql | 9.4.6 | All | All | All |
| Application | Postgresql | Postgresql | 9.4.7 | All | All | All |
| Application | Postgresql | Postgresql | 9.4.8 | All | All | All |
| Application | Postgresql | Postgresql | 9.5 | All | All | All |
| Application | Postgresql | Postgresql | 9.5.1 | All | All | All |
| Application | Postgresql | Postgresql | 9.5.2 | All | All | All |
| Application | Postgresql | Postgresql | 9.5.3 | All | All | All |
| Application | Postgresql | Postgresql | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PostgreSQL CVE-2016-5424 Multiple Local Privilege Escalation Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| PostgreSQL: Documentation: 9.6: Release 9.3.14 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Release Notes, Vendor Advisory |
| Debian -- Security Information -- DSA-3646-1 postgresql-9.4 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| PostgreSQL: Documentation: 9.6: Release 9.4.9 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Release Notes, Vendor Advisory |
| PostgreSQL: Documentation: 9.6: Release 9.5.4 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Release Notes, Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| PostgreSQL: 2016-08-11 Security Update Release | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Patch, Third Party Advisory, VDB Entry |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| PostgreSQL: Documentation: 9.6: Release 9.1.23 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Release Notes, Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| PostgreSQL: Multiple vulnerabilities (GLSA 201701-33) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| PostgreSQL: Documentation: 9.6: Release 9.2.18 | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Release Notes, Vendor Advisory |
| PostgreSQL Bugs Let Remote Authenticated Users Deny Service and Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710501 Gentoo Linux PostgreSQL Multiple Vulnerabilities (GLSA 201701-33)