CVE-2016-2193
11.04.2016, 15:59
PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| postgresql | postgresql | 9.5 |
| postgresql | postgresql | 9.5.1 |
𝑥
= Vulnerable software versions
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||
|---|---|---|---|---|---|---|---|
| libecpg6 |
| ||||||
| libpq5 |
| ||||||
| libpq5-32bit |
| ||||||
| postgresql10 |
| ||||||
| postgresql10-contrib |
| ||||||
| postgresql10-docs |
| ||||||
| postgresql10-plperl |
| ||||||
| postgresql10-plpython |
| ||||||
| postgresql10-pltcl |
| ||||||
| postgresql10-server |
| ||||||
| postgresql96 |
| ||||||
| postgresql96-contrib |
| ||||||
| postgresql96-docs |
| ||||||
| postgresql96-server |
|
Common Weakness Enumeration
References