Insecure functionality In postgresql
Description
A flaw was found in the way PostgreSQL client programs handled database and role names containing newlines, carriage returns, double quotes, or backslashes. By crafting such an object name, roles with the CREATEDB or CREATEROLE option could escalate their privileges to superuser when a superuser next executes maintenance with a vulnerable client program.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rpm rhel5 | - | - | |
rpm rhel6 | - | - | |
rpm rhel7 | 0:9.2.18-1.el7 | ||
rpm rhel5 | - | - |
Aliases
1. 2. 3.