CVE-2014-0062

Race condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE commands in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allows remote authenticated users to create an unauthorized index or read portions of unauthorized tables by creating or deleting a table with the same name during the timing window.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.9 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
VendorProductVersion
postgresqlpostgresql
𝑥
≤ 8.4.19
postgresqlpostgresql
8.4.1
postgresqlpostgresql
8.4.2
postgresqlpostgresql
8.4.3
postgresqlpostgresql
8.4.4
postgresqlpostgresql
8.4.5
postgresqlpostgresql
8.4.6
postgresqlpostgresql
8.4.7
postgresqlpostgresql
8.4.8
postgresqlpostgresql
8.4.9
postgresqlpostgresql
8.4.10
postgresqlpostgresql
8.4.11
postgresqlpostgresql
8.4.12
postgresqlpostgresql
8.4.13
postgresqlpostgresql
8.4.14
postgresqlpostgresql
8.4.15
postgresqlpostgresql
8.4.16
postgresqlpostgresql
8.4.17
postgresqlpostgresql
8.4.18
postgresqlpostgresql
9.0
postgresqlpostgresql
9.0.1
postgresqlpostgresql
9.0.2
postgresqlpostgresql
9.0.3
postgresqlpostgresql
9.0.4
postgresqlpostgresql
9.0.5
postgresqlpostgresql
9.0.6
postgresqlpostgresql
9.0.7
postgresqlpostgresql
9.0.8
postgresqlpostgresql
9.0.9
postgresqlpostgresql
9.0.10
postgresqlpostgresql
9.0.11
postgresqlpostgresql
9.0.12
postgresqlpostgresql
9.0.13
postgresqlpostgresql
9.0.14
postgresqlpostgresql
9.0.15
postgresqlpostgresql
9.1
postgresqlpostgresql
9.1.1
postgresqlpostgresql
9.1.2
postgresqlpostgresql
9.1.3
postgresqlpostgresql
9.1.4
postgresqlpostgresql
9.1.5
postgresqlpostgresql
9.1.6
postgresqlpostgresql
9.1.7
postgresqlpostgresql
9.1.8
postgresqlpostgresql
9.1.9
postgresqlpostgresql
9.1.10
postgresqlpostgresql
9.1.11
postgresqlpostgresql
9.2
postgresqlpostgresql
9.2.1
postgresqlpostgresql
9.2.2
postgresqlpostgresql
9.2.3
postgresqlpostgresql
9.2.4
postgresqlpostgresql
9.2.5
postgresqlpostgresql
9.2.6
postgresqlpostgresql
9.3
postgresqlpostgresql
9.3.1
postgresqlpostgresql
9.3.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-8.4
utopic
dne
trusty
dne
saucy
dne
quantal
dne
precise
Fixed 8.4.22-0ubuntu0.12.04
released
lucid
Fixed 8.4.20-0ubuntu010.04
released
postgresql-9.1
utopic
dne
trusty
Fixed 9.1.12-1
released
saucy
Fixed 9.1.12-0ubuntu0.13.10
released
quantal
Fixed 9.1.12-0ubuntu0.12.10
released
precise
Fixed 9.1.12-0ubuntu0.12.04
released
lucid
dne
postgresql-9.3
utopic
dne
trusty
Fixed 9.3.3-1
released
saucy
dne
quantal
dne
precise
dne
lucid
dne
References