cbcvebase.
CVE-2014-0067
published 2014-03-31

CVE-2014-0067: The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a…

PriorityP420medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.48%
38.6th percentile
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.

Affected

61 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x
applemac_os_x_server
appleos_x_server_v5.0.3
appleos_x_yosemite_v10.10.5_and_security_update_2015-006
postgresqlpostgresql<= 8.4.19
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql
postgresqlpostgresql

CVSS provenance

nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.