Sploitus

CVE-2007-6600

1 known exploit for CVE-2007-6600

PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21 uses superuser privileges instead of table owner privileges for (1) VACUUM and (2) ANALYZE operations within index functions, and supports (3) SET ROLE and (4) SET SESSION AUTHORIZATION within index functions, which allows remote authenticated users to gain privileges.

Affected products
Postgresql, Red Hat
Postgresql
= 7.3, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 7.3.10, 7.3.11, 7.3.12, 7.3.13, 7.3.14, 7.3.15, 7.3.16, 7.3.17, 7.3.18, 7.3.19, 7.4, 7.4.1, 7.4.2, 7.4.3, 7.4.4, 7.4.5, 7.4.6, 7.4.7, 7.4.8, 7.4.9, 7.4.10, 7.4.11, 7.4.12, 7.4.13, 7.4.14, 7.4.16, 7.4.17, 7.4.18, 8.0, 8.0.0
CVSS 2.0
6.5 MEDIUM
EPSS
3.1% (87th percentile)
Weakness
CWE-264
NVD status
Modified
Published
2008-01-09
CVE-2007-6600 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2007-6600

Proof-of-concept code and exploit modules indexed by Sploitus