#VU41879 Permissions, Privileges, and Access Controls in PostgreSQL Global Development Group products - CVE-2014-0067
Published: March 31, 2014 / Updated: August 10, 2020
macOS
macOS Server
PostgreSQL
Apple Inc.
PostgreSQL Global Development Group
Description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.
Remediation
External links
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00018.html
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00038.html
- http://wiki.postgresql.org/wiki/20140220securityrelease
- http://www.debian.org/security/2014/dsa-2864
- http://www.debian.org/security/2014/dsa-2865
- http://www.postgresql.org/about/news/1506/
- http://www.securityfocus.com/bid/65721
- https://support.apple.com/HT205219
- https://support.apple.com/kb/HT205031