CVE-2014-0062

Public on 2014-03-13
Modified on 2014-09-17
Description
Race condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE commands in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allows remote authenticated users to create an unauthorized index or read portions of unauthorized tables by creating or deleting a table with the same name during the timing window.
Severity
Medium severity
Medium
CVSS v3 Base Score
3.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 postgresql8 2014-03-13 ALAS-2014-305 Fixed
Amazon Linux 1 postgresql9 2014-03-13 ALAS-2014-306 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv2 3.5 AV:N/AC:M/Au:S/C:P/I:N/A:N
NVD CVSSv2 4.9 AV:N/AC:M/Au:S/C:P/I:P/A:N