Permissions, Privileges, and Access Controls in PostgreSQL - CVE-2013-1903
Published: April 4, 2013 / Updated: August 11, 2020
PostgreSQL
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
PostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly provides the superuser password to scripts related to "graphical installers for Linux and Mac OS X," which has unspecified impact and attack vectors.