CVE-2010-3433
06.10.2010, 17:00
The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| postgresql | postgresql | 7.4 |
| postgresql | postgresql | 7.4.1 |
| postgresql | postgresql | 7.4.2 |
| postgresql | postgresql | 7.4.3 |
| postgresql | postgresql | 7.4.4 |
| postgresql | postgresql | 7.4.5 |
| postgresql | postgresql | 7.4.6 |
| postgresql | postgresql | 7.4.7 |
| postgresql | postgresql | 7.4.8 |
| postgresql | postgresql | 7.4.9 |
| postgresql | postgresql | 7.4.10 |
| postgresql | postgresql | 7.4.11 |
| postgresql | postgresql | 7.4.12 |
| postgresql | postgresql | 7.4.13 |
| postgresql | postgresql | 7.4.14 |
| postgresql | postgresql | 7.4.15 |
| postgresql | postgresql | 7.4.16 |
| postgresql | postgresql | 7.4.17 |
| postgresql | postgresql | 7.4.18 |
| postgresql | postgresql | 7.4.19 |
| postgresql | postgresql | 7.4.20 |
| postgresql | postgresql | 7.4.21 |
| postgresql | postgresql | 7.4.22 |
| postgresql | postgresql | 7.4.23 |
| postgresql | postgresql | 7.4.24 |
| postgresql | postgresql | 7.4.25 |
| postgresql | postgresql | 7.4.26 |
| postgresql | postgresql | 7.4.27 |
| postgresql | postgresql | 7.4.28 |
| postgresql | postgresql | 7.4.29 |
| postgresql | postgresql | 8.0 |
| postgresql | postgresql | 8.0.1 |
| postgresql | postgresql | 8.0.2 |
| postgresql | postgresql | 8.0.3 |
| postgresql | postgresql | 8.0.4 |
| postgresql | postgresql | 8.0.5 |
| postgresql | postgresql | 8.0.6 |
| postgresql | postgresql | 8.0.7 |
| postgresql | postgresql | 8.0.8 |
| postgresql | postgresql | 8.0.9 |
| postgresql | postgresql | 8.0.10 |
| postgresql | postgresql | 8.0.11 |
| postgresql | postgresql | 8.0.12 |
| postgresql | postgresql | 8.0.13 |
| postgresql | postgresql | 8.0.14 |
| postgresql | postgresql | 8.0.15 |
| postgresql | postgresql | 8.0.16 |
| postgresql | postgresql | 8.0.17 |
| postgresql | postgresql | 8.0.18 |
| postgresql | postgresql | 8.0.19 |
| postgresql | postgresql | 8.0.20 |
| postgresql | postgresql | 8.0.21 |
| postgresql | postgresql | 8.0.22 |
| postgresql | postgresql | 8.0.23 |
| postgresql | postgresql | 8.0.24 |
| postgresql | postgresql | 8.0.25 |
| postgresql | postgresql | 8.1 |
| postgresql | postgresql | 8.1.1 |
| postgresql | postgresql | 8.1.2 |
| postgresql | postgresql | 8.1.3 |
| postgresql | postgresql | 8.1.4 |
| postgresql | postgresql | 8.1.5 |
| postgresql | postgresql | 8.1.6 |
| postgresql | postgresql | 8.1.7 |
| postgresql | postgresql | 8.1.8 |
| postgresql | postgresql | 8.1.9 |
| postgresql | postgresql | 8.1.10 |
| postgresql | postgresql | 8.1.11 |
| postgresql | postgresql | 8.1.12 |
| postgresql | postgresql | 8.1.13 |
| postgresql | postgresql | 8.1.14 |
| postgresql | postgresql | 8.1.15 |
| postgresql | postgresql | 8.1.16 |
| postgresql | postgresql | 8.1.17 |
| postgresql | postgresql | 8.1.18 |
| postgresql | postgresql | 8.1.19 |
| postgresql | postgresql | 8.1.20 |
| postgresql | postgresql | 8.1.21 |
| postgresql | postgresql | 8.2 |
| postgresql | postgresql | 8.2.1 |
| postgresql | postgresql | 8.2.2 |
| postgresql | postgresql | 8.2.3 |
| postgresql | postgresql | 8.2.4 |
| postgresql | postgresql | 8.2.5 |
| postgresql | postgresql | 8.2.6 |
| postgresql | postgresql | 8.2.7 |
| postgresql | postgresql | 8.2.8 |
| postgresql | postgresql | 8.2.9 |
| postgresql | postgresql | 8.2.10 |
| postgresql | postgresql | 8.2.11 |
| postgresql | postgresql | 8.2.12 |
| postgresql | postgresql | 8.2.13 |
| postgresql | postgresql | 8.2.14 |
| postgresql | postgresql | 8.2.15 |
| postgresql | postgresql | 8.2.16 |
| postgresql | postgresql | 8.2.17 |
| postgresql | postgresql | 8.3 |
| postgresql | postgresql | 8.3.1 |
| postgresql | postgresql | 8.3.2 |
| postgresql | postgresql | 8.3.3 |
| postgresql | postgresql | 8.3.4 |
| postgresql | postgresql | 8.3.5 |
| postgresql | postgresql | 8.3.6 |
| postgresql | postgresql | 8.3.7 |
| postgresql | postgresql | 8.3.8 |
| postgresql | postgresql | 8.3.9 |
| postgresql | postgresql | 8.3.10 |
| postgresql | postgresql | 8.3.11 |
| postgresql | postgresql | 8.4 |
| postgresql | postgresql | 8.4.1 |
| postgresql | postgresql | 8.4.2 |
| postgresql | postgresql | 8.4.3 |
| postgresql | postgresql | 8.4.4 |
| postgresql | postgresql | 9.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| postgresql-7.4 |
| ||||||||||||||||
| postgresql-8.0 |
| ||||||||||||||||
| postgresql-8.1 |
| ||||||||||||||||
| postgresql-8.2 |
| ||||||||||||||||
| postgresql-8.3 |
| ||||||||||||||||
| postgresql-8.4 |
|
openSUSE / SLES Releases
openSUSE Product | |||||
|---|---|---|---|---|---|
| libecpg6 |
| ||||
| libpq5 |
| ||||
| libpq5-32bit |
| ||||
| postgresql10 |
| ||||
| postgresql10-contrib |
| ||||
| postgresql10-docs |
| ||||
| postgresql10-plperl |
| ||||
| postgresql10-plpython |
| ||||
| postgresql10-pltcl |
| ||||
| postgresql10-server |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| postgresql |
| ||
| postgresql-contrib |
| ||
| postgresql-devel |
| ||
| postgresql-docs |
| ||
| postgresql-libs |
| ||
| postgresql-plperl |
| ||
| postgresql-plpython |
| ||
| postgresql-pltcl |
| ||
| postgresql-server |
| ||
| postgresql-test |
|
Common Weakness Enumeration
References