CVE-2013-1901
04.04.2013, 17:55
PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) pg_start_backup or (2) pg_stop_backup functions.Enginsight
| Vendor | Product | Version |
|---|---|---|
| postgresql | postgresql | 9.2 |
| postgresql | postgresql | 9.2.1 |
| postgresql | postgresql | 9.2.2 |
| postgresql | postgresql | 9.2.3 |
| postgresql | postgresql | 9.1 |
| postgresql | postgresql | 9.1.1 |
| postgresql | postgresql | 9.1.2 |
| postgresql | postgresql | 9.1.3 |
| postgresql | postgresql | 9.1.4 |
| postgresql | postgresql | 9.1.5 |
| postgresql | postgresql | 9.1.6 |
| postgresql | postgresql | 9.1.7 |
| postgresql | postgresql | 9.1.8 |
| canonical | ubuntu_linux | 8.04 |
| canonical | ubuntu_linux | 10.04 |
| canonical | ubuntu_linux | 11.10 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 12.10 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| postgresql-8.2 |
| ||||||||||
| postgresql-8.3 |
| ||||||||||
| postgresql-8.4 |
| ||||||||||
| postgresql-9.1 |
|
Common Weakness Enumeration
References