A race condition when using CREATE INDEX could cause lookups to find table names (of the same name) in the wrong schema, allowing indexes to be created on tables the caller does not own. An authenticated database user could possibly leverage this flaw to escalate their privileges. Acknowledgements: Red Hat would like to thank the PostgreSQL project for reporting this issue. Upstream acknowledges Robert Haas and Andres Freund as the original reporters.
This is now public: https://github.com/postgres/postgres/commit/5f173040e324f6c2eebb90d86cf1b0cdb5890f0a
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 5 Via RHSA-2014:0211 https://rhn.redhat.com/errata/RHSA-2014-0211.html
This issue has been addressed in following products: Red Hat Software Collections for RHEL-6 Via RHSA-2014:0221 https://rhn.redhat.com/errata/RHSA-2014-0221.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2014:0249 https://rhn.redhat.com/errata/RHSA-2014-0249.html
This issue has been addressed in following products: CloudForms Management Engine 5.x Via RHSA-2014:0469 https://rhn.redhat.com/errata/RHSA-2014-0469.html