PostgreSQL CVE-2014-0062 Security Bypass Vulnerability
BID:65727
Info
PostgreSQL CVE-2014-0062 Security Bypass Vulnerability
| Bugtraq ID: | 65727 |
| Class: | Race Condition Error |
| CVE: |
CVE-2014-0062 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 20 2014 12:00AM |
| Updated: | Oct 19 2017 03:03AM |
| Credit: | Andres Freund |
| Vulnerable: |
Ubuntu Ubuntu Linux 13.10 Ubuntu Ubuntu Linux 12.10 Ubuntu Ubuntu Linux 12.04 LTS Ubuntu Ubuntu Linux 10.04 LTS S.u.S.E. openSUSE 11.4 Redhat Software Collections for RHEL 0 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server PostgreSQL PostgreSQL 9.2.3 PostgreSQL PostgreSQL 9.1.8 PostgreSQL PostgreSQL 9.1.3 PostgreSQL PostgreSQL 9.0.12 PostgreSQL PostgreSQL 9.0.7 PostgreSQL PostgreSQL 9.0.3 PostgreSQL PostgreSQL 9.0.1 PostgreSQL PostgreSQL 9.0 PostgreSQL PostgreSQL 8.4.17 PostgreSQL PostgreSQL 8.4.16 PostgreSQL PostgreSQL 8.4.15 PostgreSQL PostgreSQL 8.4.14 PostgreSQL PostgreSQL 8.4.11 PostgreSQL PostgreSQL 8.4.10 PostgreSQL PostgreSQL 8.4.9 PostgreSQL PostgreSQL 8.4.8 PostgreSQL PostgreSQL 8.4.7 PostgreSQL PostgreSQL 8.4.6 PostgreSQL PostgreSQL 8.4.5 PostgreSQL PostgreSQL 8.4.4 PostgreSQL PostgreSQL 8.4.3 PostgreSQL PostgreSQL 8.4.2 PostgreSQL PostgreSQL 8.4.1 PostgreSQL PostgreSQL 9.3 PostgreSQL PostgreSQL 9.2.4-1 PostgreSQL PostgreSQL 9.2.4 PostgreSQL PostgreSQL 9.2.2-1 PostgreSQL PostgreSQL 9.2.2 PostgreSQL PostgreSQL 9.2.1 PostgreSQL PostgreSQL 9.2 PostgreSQL PostgreSQL 9.1.9-1 PostgreSQL PostgreSQL 9.1.9 PostgreSQL PostgreSQL 9.1.7 PostgreSQL PostgreSQL 9.1.6 PostgreSQL PostgreSQL 9.1.5 PostgreSQL PostgreSQL 9.1.4 PostgreSQL PostgreSQL 9.1.2 PostgreSQL PostgreSQL 9.1.1 PostgreSQL PostgreSQL 9.1 PostgreSQL PostgreSQL 9.0.9 PostgreSQL PostgreSQL 9.0.8 PostgreSQL PostgreSQL 9.0.6 PostgreSQL PostgreSQL 9.0.5 PostgreSQL PostgreSQL 9.0.4 PostgreSQL PostgreSQL 9.0.2 PostgreSQL PostgreSQL 9.0.13-1 PostgreSQL PostgreSQL 9.0.13 PostgreSQL PostgreSQL 9.0.11 PostgreSQL PostgreSQL 9.0.10 PostgreSQL PostgreSQL 8.4.17-1 PostgreSQL PostgreSQL 8.4.13 PostgreSQL PostgreSQL 8.4.12 PostgreSQL PostgreSQL 8.4 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Oracle Communications WebRTC Session Controller 7.2 Oracle Communications WebRTC Session Controller 7.1 Oracle Communications WebRTC Session Controller 7.0 Nixu NameSurfer 7.5.2 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Juniper Security Threat Response Manager 2012.1 IBM Tivoli Business Service Manager 4.2.1 IBM Tivoli Business Service Manager 4.2 IBM QRadar Security Information and Event Manager 7.0 MR5 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 5 Avaya IP Office Server Edition 9.0 Avaya IP Office Application Server 9.0 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya CMS R17ac.h Avaya CMS R17ac.g Avaya Aura Conferencing 7.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard Avaya Aura Communication Manager Utility Services 6.3 Avaya Aura Communication Manager Utility Services 6.2.5.0.15 Avaya Aura Communication Manager Utility Services 6.2.4.0.15 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1.0.9.8 Avaya Aura Communication Manager Utility Services 6.1 SP 6.1.0.9.8 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.2 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.4 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Apple Mac OS X Server 3.0 Apple Mac OS X Server 2.0 Apple Mac OS X 10.9.5 |
| Not Vulnerable: |
PostgreSQL PostgreSQL 9.3.3 PostgreSQL PostgreSQL 9.2.7 PostgreSQL PostgreSQL 9.1.12 PostgreSQL PostgreSQL 9.0.16 PostgreSQL PostgreSQL 8.4.20 Nixu NameSurfer 7.5.2.1 Juniper Security Threat Response Manager 2012.1R8 Apple Mac OS X Server 3.2.1 Apple Mac OS X Server 4.0 |
Discussion
PostgreSQL CVE-2014-0062 Security Bypass Vulnerability
PostgreSQL is prone to a security-bypass vulnerability.
Successful exploits may allow an attacker to bypass certain security restrictions and perform unauthorized actions, which may lead to further attacks.
Versions prior to PostgreSQL 9.3.3, 9.2.7, 9.1.12, 9.0.16, and 8.4.20 are vulnerable.
PostgreSQL is prone to a security-bypass vulnerability.
Successful exploits may allow an attacker to bypass certain security restrictions and perform unauthorized actions, which may lead to further attacks.
Versions prior to PostgreSQL 9.3.3, 9.2.7, 9.1.12, 9.0.16, and 8.4.20 are vulnerable.
Exploit / POC
PostgreSQL CVE-2014-0062 Security Bypass Vulnerability
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PostgreSQL CVE-2014-0062 Security Bypass Vulnerability
References:
References:
- postgresql security update (RHSA-2014-0249) (Avaya)
- 20140220securityrelease (PostgreSQL)
- About the security content of OS X Server v4.0 (Apple)
- IBM QRadar Security Information and Event Manager 7.0 MR5 contains multiple vuln (IBM)
- Juniper Secure Analytics (JSA)/Security Threat Response Manager (STRM): Multiple (Juniper)
- PostgreSQL 9.3.3, 9.2.7, 9.1.12, 9.0.16 and 8.4.20 released! (PostgreSQL)
- PostgreSQL Homepage (PostgreSQL)
- Oracle Critical Patch Update Advisory - October 2017 (Oracle)
- postgresql84 and postgresql security update (RHSA-2014-0211) (Avaya)
- Security Vulnerabilities reported in Tivoli Business Service Manager (ibm)