PostgreSQL CVE-2014-0060 Security Bypass Vulnerability
BID:65723
Info
PostgreSQL CVE-2014-0060 Security Bypass Vulnerability
| Bugtraq ID: | 65723 |
| Class: | Access Validation Error |
| CVE: |
CVE-2014-0060 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2014 12:00AM |
| Updated: | Apr 13 2015 10:24PM |
| Credit: | Noah Misch and Jonas Sundman |
| Vulnerable: |
Ubuntu Ubuntu Linux 10.04 LTS SuSE openSUSE 11.4 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Puppet Labs Puppet Enterprise 2.5.1 Puppet Labs Puppet Enterprise 2.0.3 Puppet Labs Puppet Enterprise 2.0.2 Puppet Labs Puppet Enterprise 2.6 Puppet Labs Puppet Enterprise 1.2 Puppet Labs Puppet Enterprise 1.1 Puppet Labs Puppet Enterprise 1.0 Puppet Labs Puppet Enterprise 2.0 PostgreSQL PostgreSQL 9.0 PostgreSQL PostgreSQL 9.2 PostgreSQL PostgreSQL 9.1 PostgreSQL PostgreSQL 8.4 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 IBM Tivoli Business Service Manager 4.2.1 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 5 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: | |
Discussion
PostgreSQL CVE-2014-0060 Security Bypass Vulnerability
PostgreSQL is prone to a security-bypass vulnerability.
An attacker may leverage this issue to bypass certain security restrictions and perform unauthorized actions.
Versions prior to PostgreSQL 9.3.3, 9.2.7, 9.1.12, 9.0.16, and 8.4.20 are vulnerable.
PostgreSQL is prone to a security-bypass vulnerability.
An attacker may leverage this issue to bypass certain security restrictions and perform unauthorized actions.
Versions prior to PostgreSQL 9.3.3, 9.2.7, 9.1.12, 9.0.16, and 8.4.20 are vulnerable.
Exploit / POC
PostgreSQL CVE-2014-0060 Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PostgreSQL CVE-2014-0060 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
PostgreSQL CVE-2014-0060 Security Bypass Vulnerability
References:
References:
- postgresql security update (RHSA-2014-0249) (Avaya)
- About the security content of OS X Server v4.0 (Apple)
- Bug 1065219 - (CVE-2014-0060) CVE-2014-0060 postgresql: SET ROLE without ADMIN O (Red Hat Bugzilla)
- CVE-2014-0060 (PostgreSQL security bypass vulnerability) (Puppet Labs)
- IBM QRadar Security Information and Event Manager 7.0 MR5 contains multiple vuln (IBM)
- Juniper Secure Analytics (JSA)/Security Threat Response Manager (STRM): Multiple (Juniper)
- PostgreSQL Homepage (PostgreSQL)
- Shore up ADMIN OPTION restrictions. (GitHub)
- postgresql84 and postgresql security update (RHSA-2014-0211) (Avaya)
- Security Vulnerabilities reported in Tivoli Business Service Manager (ibm)