CVE-2007-2138
Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the…
Does this matter?
Lower severity and a low EPSS score (3.69%). Track it; it rarely justifies an emergency change on its own.
Description
Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner, related to "search_path settings."
- CVSS 2.0
- 6.0 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
- EPSS
- 3.69% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- postgresql/postgresql · debian/debian linux · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://rhn.redhat.com/errata/RHSA-2007-0336.htmlThird Party Advisory
- http://secunia.com/advisories/24989Third Party Advisory
- http://secunia.com/advisories/24999Third Party Advisory
- http://secunia.com/advisories/25005Third Party Advisory
- http://secunia.com/advisories/25019Third Party Advisory
- http://secunia.com/advisories/25037Third Party Advisory
- http://secunia.com/advisories/25058Third Party Advisory
- http://secunia.com/advisories/25184Third Party Advisory
- http://secunia.com/advisories/25238Third Party Advisory
- http://secunia.com/advisories/25334Third Party Advisory
- http://secunia.com/advisories/25717Third Party Advisory
- http://secunia.com/advisories/25720Third Party Advisory
- http://secunia.com/advisories/25725Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200705-12.xmlThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102894-1Broken Link
- http://support.avaya.com/elmodocs2/security/ASA-2007-190.htmThird Party Advisory
- http://www.debian.org/security/2007/dsa-1309Third Party Advisory
- http://www.debian.org/security/2007/dsa-1311Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:094Third Party Advisory
- http://www.postgresql.org/about/news.791Patch, Vendor Advisory
- http://www.postgresql.org/support/security.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0337.htmlThird Party Advisory
- http://www.securityfocus.com/bid/23618Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1017974Third Party Advisory, VDB Entry
- http://www.trustix.org/errata/2007/0015/Broken Link
- http://www.ubuntu.com/usn/usn-454-1Third Party Advisory
- http://www.vupen.com/english/advisories/2007/1497Third Party Advisory
- http://www.vupen.com/english/advisories/2007/1549Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33842Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1292Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.