PostgreSQL 8.1.0 through 8.1.2 allows authenticated database users to gain additional privileges via "knowledge of the backend protocol" using a crafted SET ROLE to other database users, a different vulnerability than CVE-2006-0678.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-02-14 11:06
Updated : 2018-10-19 08:45
NVD link : CVE-2006-0553
Mitre link : CVE-2006-0553
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
postgresql
- postgresql