New Search

CREATE TRIGGER in PostgreSQL 8.3.x before 8.3.18 8.4.x before 8.4.11 9.0.x before 9.0.7 and 9.1.x before 9.1.3 (CVE-2012-0866)

oval:org.cisecurity:def:8228

CREATE TRIGGER in PostgreSQL 8.3.x before 8.3.18 8.4.x before 8.4.11 9.0.x before 9.0.7 and 9.1.x before 9.1.3 does not properly check the execute permission for trigger functions marked SECURITY DEFINER which allows remote authenticated users to execute otherwise restricted triggers on arbitrary data by installing the trigger on an attacker-owned table.

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows Server 2008
  • Microsoft Windows Server 2012
  • Microsoft Windows 8.1
  • Microsoft Windows 7
  • Microsoft Windows 8
  • Microsoft Windows Vista
  • Microsoft Windows Server 2016
  • Microsoft Windows 10
  • Microsoft Windows Server 2003
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows XP
  • Microsoft Windows Server 2012 R2
Class:
vulnerability
Reference(s):
  • CVE-2012-0866
Product(s):
  • PostgreSQL