Security Advisory

CVE-2009-4136

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-12-15 18:00:00
Last updated 2024-08-07 06:54:09
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly manage session-local state during execution of an index function by a database superuser, which allows remote authenticated users to gain privileges via a table with crafted index functions, as demonstrated by functions that modify (1) search_path or (2) a prepared statement, a related issue to CVE-2007-6600 and CVE-2009-3230.