Security Advisory

CVE-2007-2138

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-04-24 20:00:00
Last updated 2024-08-07 13:23:50
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner, related to "search_path settings."