CVE-2014-0067

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.

References

http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html

http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html

http://lists.opensuse.org/opensuse-updates/2014-03/msg00018.html

http://lists.opensuse.org/opensuse-updates/2014-03/msg00038.html

http://wiki.postgresql.org/wiki/20140220securityrelease

http://www.debian.org/security/2014/dsa-2864

http://www.debian.org/security/2014/dsa-2865

http://www.postgresql.org/about/news/1506/

http://www.securityfocus.com/bid/65721

https://support.apple.com/HT205219

https://support.apple.com/kb/HT205031

Details

Source: MITRE

Published: 2014-03-31

Updated: 2017-12-16

Type: CWE-264

Risk Information

CVSS v2

Base Score: 4.6

Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 3.9

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:apple:mac_os_x:10.10.4:*:*:*:*:*:*:*

cpe:2.3:o:apple:mac_os_x_server:5.0.3:*:*:*:*:*:*:*

Configuration 2

OR

cpe:2.3:a:postgresql:postgresql:8.4.1:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.2:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.3:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.4:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.5:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.6:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.7:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.8:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.9:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.10:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.11:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.12:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.13:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.14:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.15:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.16:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.17:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:8.4.18:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* versions up to 8.4.19 (inclusive)

cpe:2.3:a:postgresql:postgresql:9.0:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.0.1:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.0.2:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.0.3:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.0.4:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.0.5:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.0.6:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.0.7:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.0.8:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.0.9:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.0.10:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.0.11:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.0.12:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.0.13:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.0.14:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.0.15:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.1:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.1.1:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.1.2:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.1.3:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.1.4:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.1.5:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.1.6:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.1.7:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.1.8:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.1.9:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.1.10:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.1.11:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.2:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.2.1:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.2.2:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.2.3:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.2.4:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.2.5:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.2.6:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.3:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.3.1:*:*:*:*:*:*:*

cpe:2.3:a:postgresql:postgresql:9.3.2:*:*:*:*:*:*:*

Tenable Plugins

View all (15 total)

IDNameProductFamilySeverity
8981Mac OS X < 10.10.5 Multiple VulnerabilitiesNessus Network MonitorOperating System Detection
high
86066Mac OS X : OS X Server < 5.0.3 Multiple VulnerabilitiesNessusMacOS X Local Security Checks
critical
85409Mac OS X Multiple Vulnerabilities (Security Update 2015-006)NessusMacOS X Local Security Checks
high
85408Mac OS X 10.10.x < 10.10.5 Multiple VulnerabilitiesNessusMacOS X Local Security Checks
high
8727PostgreSQL 9.0 < 9.0.19 / 9.1 < 9.1.15 / 9.2 < 9.2.10 / 9.3 < 9.3.6 / 9.4 < 9.4.1 Multiple VulnerabilitiesNessus Network MonitorDatabase
high
82363Mandriva Linux Security Advisory : postgresql (MDVSA-2015:110)NessusMandriva Local Security Checks
medium
82167Debian DLA-19-1 : postgresql-8.4 updateNessusDebian Local Security Checks
medium
81828Amazon Linux AMI : postgresql92 (ALAS-2015-492)NessusAmazon Linux Local Security Checks
critical
81300PostgreSQL 9.0 < 9.0.19 / 9.1 < 9.1.15 / 9.2 < 9.2.10 / 9.3 < 9.3.6 / 9.4 < 9.4.1 Multiple VulnerabilitiesNessusDatabases
high
75281openSUSE Security Update : postgresql92 (openSUSE-SU-2014:0345-1)NessusSuSE Local Security Checks
medium
73268SuSE 11.3 Security Update : PostgreSQL 9.1 (SAT Patch Number 8970)NessusSuSE Local Security Checks
medium
72642Mandriva Linux Security Advisory : postgresql (MDVSA-2014:047)NessusMandriva Local Security Checks
medium
72612FreeBSD : PostgreSQL -- multiple privilege issues (42d42090-9a4d-11e3-b029-08002798f6ff)NessusFreeBSD Local Security Checks
medium
72611Debian DSA-2865-1 : postgresql-9.1 - several vulnerabilitiesNessusDebian Local Security Checks
medium
72610Debian DSA-2864-1 : postgresql-8.4 - several vulnerabilitiesNessusDebian Local Security Checks
medium