PostgreSQL Remote SET ROLE Privilege Escalation Vulnerability
BID:16649
Info
PostgreSQL Remote SET ROLE Privilege Escalation Vulnerability
| Bugtraq ID: | 16649 |
| Class: | Access Validation Error |
| CVE: |
CVE-2006-0553 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 14 2006 12:00AM |
| Updated: | Feb 22 2006 04:22PM |
| Credit: | Akio Ishida is credited with the discovery of this vulnerability. |
| Vulnerable: |
PostgreSQL PostgreSQL 8.1.1 PDGSoft Shopping Cart 8.1.2 PDGSoft Shopping Cart 8.1 OpenPKG OpenPKG 2.5 OpenPKG OpenPKG 2.4 OpenPKG OpenPKG 2.3 OpenPKG OpenPKG Current |
| Not Vulnerable: |
PostgreSQL PostgreSQL 8.1.3 |
Discussion
PostgreSQL Remote SET ROLE Privilege Escalation Vulnerability
PostgreSQL is susceptible to a remote privilege-escalation vulnerability. This issue is due to a flaw in the error path of the 'SET ROLE' function.
This issue allows remote attackers with database access to gain administrative access to affected database servers. Since such access also allows filesystem access, other attacks against the underlying operating system may also be possible.
PostgreSQL is susceptible to a remote privilege-escalation vulnerability. This issue is due to a flaw in the error path of the 'SET ROLE' function.
This issue allows remote attackers with database access to gain administrative access to affected database servers. Since such access also allows filesystem access, other attacks against the underlying operating system may also be possible.
Exploit / POC
PostgreSQL Remote SET ROLE Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
PostgreSQL Remote SET ROLE Privilege Escalation Vulnerability
Solution:
Please see the referenced advisories for further information:
- The vendor has released PostgreSQL version 8.1.3, along with an advisory to address this issue.
- OpenPKG has released security advisory OpenPKG-SA-2006.004 to address this issue.
PDGSoft Shopping Cart 8.1
PostgreSQL PostgreSQL 8.1.1
PDGSoft Shopping Cart 8.1.2
Solution:
Please see the referenced advisories for further information:
- The vendor has released PostgreSQL version 8.1.3, along with an advisory to address this issue.
- OpenPKG has released security advisory OpenPKG-SA-2006.004 to address this issue.
PDGSoft Shopping Cart 8.1
-
PostgreSQL postgresql-8.1.3.tar.bz2
http://wwwmaster.postgresql.org/download/mirrors-ftp?file=source%2Fv8. 1.3%2Fpostgresql-8.1.3.tar.bz2
PostgreSQL PostgreSQL 8.1.1
-
PostgreSQL postgresql-8.1.3.tar.bz2
http://wwwmaster.postgresql.org/download/mirrors-ftp?file=source%2Fv8. 1.3%2Fpostgresql-8.1.3.tar.bz2
PDGSoft Shopping Cart 8.1.2
-
PostgreSQL postgresql-8.1.3.tar.bz2
http://wwwmaster.postgresql.org/download/mirrors-ftp?file=source%2Fv8. 1.3%2Fpostgresql-8.1.3.tar.bz2
References
PostgreSQL Remote SET ROLE Privilege Escalation Vulnerability
References:
References:
- Minor Release 8.1.3 Patches Security Issue (PostgreSQL)
- PostgreSQL 8.1 and prior changelogs (PostgreSQL)
- PostgreSQL Project Homepage (PostgreSQL)
- PostgreSQL security releases 8.1.3, 8.0.7, 7.4.12, 7.3.14 (PostgreSQL Security
)