6

CVE-2007-2138

Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner, related to "search_path settings."

Data is provided by the National Vulnerability Database (NVD)
PostgresqlPostgresql Version < 7.3.19
PostgresqlPostgresql Version >= 7.4 < 7.4.17
PostgresqlPostgresql Version >= 8.0 < 8.0.13
PostgresqlPostgresql Version >= 8.1 < 8.1.9
PostgresqlPostgresql Version >= 8.2 < 8.2.4
DebianDebian Linux Version3.1
DebianDebian Linux Version4.0
CanonicalUbuntu Linux Version6.06 SwEditionlts
CanonicalUbuntu Linux Version6.10
CanonicalUbuntu Linux Version7.04
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.28% 0.787
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
http://www.securityfocus.com/bid/23618
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1017974
Third Party Advisory
VDB Entry