CVE DATABASE / CVE-2009-3230
CVE-2009-3230
CVSS 6.5 · MEDIUM
Summary
The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7.4.26 does not use the appropriate privileges for the (1) RESET ROLE and (2) RESET SESSION AUTHORIZATION operations, which allows remote authenticated users to gain privileges. NOTE: this is due to an incomplete fix for CVE-2007-6600.
CVSS 2.0 breakdown
| Base score | 6.5 (MEDIUM) |
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
| Attack vector | NETWORK |
| Attack complexity | LOW |
| Confidentiality | PARTIAL |
| Integrity | PARTIAL |
| Availability | PARTIAL |
Weakness type (CWE)
Affected products
Postgresql postgresql
Check this CVE live
Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.
References
- http://archives.postgresql.org/pgsql-www/2009-09/msg00024.php
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html
- http://marc.info/?l=bugtraq&m=134124585221119&w=2
- http://secunia.com/advisories/36660
- http://secunia.com/advisories/36695
- http://secunia.com/advisories/36727
- http://secunia.com/advisories/36800
- http://secunia.com/advisories/36837
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-270408-1
- http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0012
- http://www.postgresql.org/docs/8.3/static/release-8-3-8.html
- http://www.postgresql.org/support/security.html
- http://www.securityfocus.com/archive/1/509917/100/0/threaded
- http://www.securityfocus.com/bid/36314
Data: NIST NVD. NVD last modified 2026-04-23. Always verify against the vendor advisory before acting.