Name | CVE-2007-2138 |
Description | Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner, related to "search_path settings." |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-1309-1, DSA-1311-1 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
postgresql | source | sarge | 7.4.7-6sarge5 | DSA-1311-1 | ||
postgresql-7.4 | source | etch | 1:7.4.17-0etch1 | DSA-1311-1 | ||
postgresql-7.4 | source | (unstable) | 1:7.4.17-1 | |||
postgresql-8.1 | source | etch | 8.1.9-0etch1 | DSA-1309-1 | ||
postgresql-8.1 | source | (unstable) | 8.1.9-1 | |||
postgresql-8.2 | source | (unstable) | 8.2.4-1 |