CVE-2014-0067
published 2014-03-31CVE-2014-0067: The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a…
PriorityP420medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.48%
38.6th percentile
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.
Affected
61 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| apple | os_x_server_v5.0.3 | — | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| postgresql | postgresql | <= 8.4.19 | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
postgresql: Vulnerability during "make check"
vendor_redhat·2014-02-17·CVSS 4.6
CVE-2014-0067 [MEDIUM] postgresql: Vulnerability during "make check"
postgresql: Vulnerability during "make check"
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.
Statement: Not vulnerable. This issue did not affect postgresql packages as shipped with Red Hat Enterprise Linux and Red Hat Software Collections. Refer to bug 1065863 for further details: https://bugzilla.redhat.com/show_bug.cgi?id=1065863
Package: postgresql (Red Hat Enterprise Linux 5) - Will not fix
Package: postgresql84 (Red Hat Enterprise Linux 5) - Will not fix
Package: postgresql (Red Hat Enterprise Linux 6) - Will not fix
Package: postgresql92-postgre
Apple
CVE-2014-0067: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 4.6
CVE-2014-0067 [MEDIUM] CVE-2014-0067: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2014-0067
Component: CVE-2014-0067
Apple
CVE-2014-0067: OS X Server v5.0.3
vendor_apple·CVSS 4.6
CVE-2014-0067 [MEDIUM] CVE-2014-0067: OS X Server v5.0.3
Apple Security Update: About the security content of OS X Server v5.0.3
Product: OS X Server v5.0.3
CVE: CVE-2014-0067
Component: CVE-2014-0067
GHSA
GHSA-gmhx-6jh3-87c2: The "make check" command for the test suites in PostgreSQL 9
ghsa_unreviewed·2022-05-17
CVE-2014-0067 [MEDIUM] GHSA-gmhx-6jh3-87c2: The "make check" command for the test suites in PostgreSQL 9
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.
OSV
CVE-2014-0067: The "make check" command for the test suites in PostgreSQL 9
osv·2014-03-31·CVSS 4.6
CVE-2014-0067 [MEDIUM] CVE-2014-0067: The "make check" command for the test suites in PostgreSQL 9
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00018.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00038.htmlhttp://wiki.postgresql.org/wiki/20140220securityreleasehttp://www.debian.org/security/2014/dsa-2864http://www.debian.org/security/2014/dsa-2865http://www.postgresql.org/about/news/1506/http://www.securityfocus.com/bid/65721https://support.apple.com/HT205219https://support.apple.com/kb/HT205031http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00018.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00038.htmlhttp://wiki.postgresql.org/wiki/20140220securityreleasehttp://www.debian.org/security/2014/dsa-2864http://www.debian.org/security/2014/dsa-2865http://www.postgresql.org/about/news/1506/http://www.securityfocus.com/bid/65721https://support.apple.com/HT205219https://support.apple.com/kb/HT205031
2014-03-31
Published