CVE-2007-6600
PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21 uses superuser privileges instead of table owner privileges for (1) VACUUM and (2) ANALYZE operations within index functions, and supports (3) SET ROLE and (4) SET SESSION AUTHORIZATION within index functions, which allows remote authenticated users to gain privileges.
- Affected products
- Postgresql, Red Hat
- Postgresql
- = 7.3, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 7.3.10, 7.3.11, 7.3.12, 7.3.13, 7.3.14, 7.3.15, 7.3.16, 7.3.17, 7.3.18, 7.3.19, 7.4, 7.4.1, 7.4.2, 7.4.3, 7.4.4, 7.4.5, 7.4.6, 7.4.7, 7.4.8, 7.4.9, 7.4.10, 7.4.11, 7.4.12, 7.4.13, 7.4.14, 7.4.16, 7.4.17, 7.4.18, 8.0, 8.0.0
- CVSS 2.0
- 6.5 MEDIUM
- EPSS
- 3.1% (87th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2008-01-09
CVE-2007-6600 at NVD
1 known exploit for CVE-2007-6600
Proof-of-concept code and exploit modules indexed by Sploitus