Bug 1065220 (CVE-2014-0061)

Summary: CVE-2014-0061 postgresql: privilege escalation via procedural language validator functions
Product: [Other] Security Response Reporter: Murray McAllister <mmcallis>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: dajohnso, gmollett, praiskup, security-response-team, xlecauch
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-20 10:43:03 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1065839, 1065840, 1065841, 1065842, 1065843, 1065844, 1065845, 1065855, 1065861, 1069071, 1069072    
Bug Blocks: 1065240, 1095075    

Description Murray McAllister 2014-02-14 07:11:24 UTC
It was found that the procedural language (PLs) validator functions could possibly be leveraged for limited code execution. An authenticated database user could possibly use this flaw to escalate their privileges.

Acknowledgements:

Red Hat would like to thank the PostgreSQL project for reporting this issue. Upstream acknowledges Andres Freund as the original reporter.

Comment 7 errata-xmlrpc 2014-02-25 16:44:06 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6
  Red Hat Enterprise Linux 5

Via RHSA-2014:0211 https://rhn.redhat.com/errata/RHSA-2014-0211.html

Comment 8 errata-xmlrpc 2014-02-27 18:23:28 UTC
This issue has been addressed in following products:

  Red Hat Software Collections for RHEL-6

Via RHSA-2014:0221 https://rhn.redhat.com/errata/RHSA-2014-0221.html

Comment 9 errata-xmlrpc 2014-03-04 19:11:30 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2014:0249 https://rhn.redhat.com/errata/RHSA-2014-0249.html

Comment 11 errata-xmlrpc 2014-05-12 18:13:34 UTC
This issue has been addressed in following products:

  CloudForms Management Engine 5.x

Via RHSA-2014:0469 https://rhn.redhat.com/errata/RHSA-2014-0469.html