OpenPKG Security Advisory
OpenPKG-SA-2006.004
Publisher Name: OpenPKG GmbH
Publisher Home: http://openpkg.com/
Advisory Id (public): OpenPKG-SA-2006.004
Advisory Type: OpenPKG Security Advisory (SA)
Advisory Directory: http://openpkg.com/go/OpenPKG-SA
Advisory Document: http://openpkg.com/go/OpenPKG-SA-2006.004
Advisory Published: 2008-08-07 22:00 UTC
Issue Id (internal): OpenPKG-SI-20060219.01
Issue First Created: 2006-02-19
Issue Last Modified: 2006-12-07
Issue Revision: 07
Subject Name: PostgreSQL
Subject Summary: PostgreSQL Database
Subject Home: http://www.postgresql.org/
Subject Versions: * <= 8.1.2
Vulnerability Id: CVE-2006-0553
Vulnerability Scope: global (not OpenPKG specific)
Attack Feasibility: run-time
Attack Vector: local system
Attack Impact: privilege escalation
Description:
According to vendor security information [0], privilege escalation
vulnerabilitiesd exist in the PostgreSQL RDBMS [1] before version
8.1.3. The bug allowed any logged-in user to "SET ROLE" to any other
database user id. Due to inadequate validity checking, a user could
exploit the special case that "SET ROLE" normally uses to restore the
previous role setting after an error. This allowed ordinary users to
acquire superuser status, for example.
The escalation of privilege risk exists only in versions 8.1.0 to
8.1.2. However, in all versions back to 7.3 there is a related bug in
"SET SESSION AUTHORIZATION" that allows unprivileged users to crash
the server, if it has been compiled with Asserts enabled (which is not
the default).
References:
[0] http://www.postgresql.org/docs/8.1/static/release.html#RELEASE-8-1-3
[1] http://www.postgresql.org/
Primary Package Name: postgresql
Primary Package Home: http://openpkg.org/go/package/postgresql
Affected Distribution: Affected Branch: Affected Package:
OpenPKG Community 2.3-SOLID postgresql-8.0.1-2.3.1
OpenPKG Community 2.4-SOLID postgresql-8.0.3-2.4.0
OpenPKG Community 2.5-SOLID postgresql-8.0.4-2.5.0
OpenPKG Community CURRENT postgresql-8.1.2-20060211
Corrected Distribution: Corrected Branch: Corrected Package:
OpenPKG Community 2.3-SOLID postgresql-8.0.1-2.3.2
OpenPKG Community 2.4-SOLID postgresql-8.0.3-2.4.1
OpenPKG Community 2.5-SOLID postgresql-8.0.4-2.5.1
OpenPKG Community CURRENT postgresql-8.1.3-20060213