CVE
- Id
- 25495
- CVE No.
- CVE-2007-2138
- Status
- Candidate
- Description
- Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner, related to "search_path settings."
- Phase
- Assigned (20070418)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
254487 | 25495 | CVE-2007-2138 | CONFIRM:http://www.postgresql.org/about/news.791 | View |
254488 | 25495 | CVE-2007-2138 | CONFIRM:http://www.postgresql.org/support/security.html | View |
254489 | 25495 | CVE-2007-2138 | CONFIRM:https://issues.rpath.com/browse/RPL-1292 | View |
254490 | 25495 | CVE-2007-2138 | CONFIRM:http://support.avaya.com/elmodocs2/security/ASA-2007-190.htm | View |
254491 | 25495 | CVE-2007-2138 | DEBIAN:DSA-1309 | View |
254492 | 25495 | CVE-2007-2138 | URL:http://www.debian.org/security/2007/dsa-1309 | View |
254493 | 25495 | CVE-2007-2138 | DEBIAN:DSA-1311 | View |
254494 | 25495 | CVE-2007-2138 | URL:http://www.debian.org/security/2007/dsa-1311 | View |
254495 | 25495 | CVE-2007-2138 | GENTOO:GLSA-200705-12 | View |
254496 | 25495 | CVE-2007-2138 | URL:http://security.gentoo.org/glsa/glsa-200705-12.xml | View |
254497 | 25495 | CVE-2007-2138 | MANDRIVA:MDKSA-2007:094 | View |
254498 | 25495 | CVE-2007-2138 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2007:094 | View |
254499 | 25495 | CVE-2007-2138 | REDHAT:RHSA-2007:0337 | View |
254500 | 25495 | CVE-2007-2138 | URL:http://www.redhat.com/support/errata/RHSA-2007-0337.html | View |
254501 | 25495 | CVE-2007-2138 | REDHAT:RHSA-2007:0336 | View |
254502 | 25495 | CVE-2007-2138 | URL:http://rhn.redhat.com/errata/RHSA-2007-0336.html | View |
254503 | 25495 | CVE-2007-2138 | SUNALERT:102894 | View |
254504 | 25495 | CVE-2007-2138 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-102894-1 | View |
254505 | 25495 | CVE-2007-2138 | TRUSTIX:2007-0015 | View |
254506 | 25495 | CVE-2007-2138 | URL:http://www.trustix.org/errata/2007/0015/ | View |
254507 | 25495 | CVE-2007-2138 | UBUNTU:USN-454-1 | View |
254508 | 25495 | CVE-2007-2138 | URL:http://www.ubuntu.com/usn/usn-454-1 | View |
254509 | 25495 | CVE-2007-2138 | BID:23618 | View |
254510 | 25495 | CVE-2007-2138 | URL:http://www.securityfocus.com/bid/23618 | View |
254511 | 25495 | CVE-2007-2138 | OVAL:oval:org.mitre.oval:def:10090 | View |
254512 | 25495 | CVE-2007-2138 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10090 | View |
254513 | 25495 | CVE-2007-2138 | VUPEN:ADV-2007-1497 | View |
254514 | 25495 | CVE-2007-2138 | URL:http://www.vupen.com/english/advisories/2007/1497 | View |
254515 | 25495 | CVE-2007-2138 | VUPEN:ADV-2007-1549 | View |
254516 | 25495 | CVE-2007-2138 | URL:http://www.vupen.com/english/advisories/2007/1549 | View |
254517 | 25495 | CVE-2007-2138 | SECTRACK:1017974 | View |
254518 | 25495 | CVE-2007-2138 | URL:http://www.securitytracker.com/id?1017974 | View |
254519 | 25495 | CVE-2007-2138 | SECUNIA:25019 | View |
254520 | 25495 | CVE-2007-2138 | URL:http://secunia.com/advisories/25019 | View |
254521 | 25495 | CVE-2007-2138 | SECUNIA:25005 | View |
254522 | 25495 | CVE-2007-2138 | URL:http://secunia.com/advisories/25005 | View |
254523 | 25495 | CVE-2007-2138 | SECUNIA:24989 | View |
254524 | 25495 | CVE-2007-2138 | URL:http://secunia.com/advisories/24989 | View |
254525 | 25495 | CVE-2007-2138 | SECUNIA:25037 | View |
254526 | 25495 | CVE-2007-2138 | URL:http://secunia.com/advisories/25037 | View |
254527 | 25495 | CVE-2007-2138 | SECUNIA:24999 | View |
254528 | 25495 | CVE-2007-2138 | URL:http://secunia.com/advisories/24999 | View |
254529 | 25495 | CVE-2007-2138 | SECUNIA:25058 | View |
254530 | 25495 | CVE-2007-2138 | URL:http://secunia.com/advisories/25058 | View |
254531 | 25495 | CVE-2007-2138 | SECUNIA:25184 | View |
254532 | 25495 | CVE-2007-2138 | URL:http://secunia.com/advisories/25184 | View |
254533 | 25495 | CVE-2007-2138 | SECUNIA:25238 | View |
254534 | 25495 | CVE-2007-2138 | URL:http://secunia.com/advisories/25238 | View |
254535 | 25495 | CVE-2007-2138 | SECUNIA:25334 | View |
254536 | 25495 | CVE-2007-2138 | URL:http://secunia.com/advisories/25334 | View |
254537 | 25495 | CVE-2007-2138 | SECUNIA:25717 | View |
254538 | 25495 | CVE-2007-2138 | URL:http://secunia.com/advisories/25717 | View |
254539 | 25495 | CVE-2007-2138 | SECUNIA:25725 | View |
254540 | 25495 | CVE-2007-2138 | URL:http://secunia.com/advisories/25725 | View |
254541 | 25495 | CVE-2007-2138 | SECUNIA:25720 | View |
254542 | 25495 | CVE-2007-2138 | URL:http://secunia.com/advisories/25720 | View |
254543 | 25495 | CVE-2007-2138 | XF:postgresql-searchpath-privilege-escalation(33842) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
53156 | JVNDB-2007-001848 | Franklin Huang Flip の everything.php における PHP リモートファイルインクルージョンの脆弱性 | Franklin Huang Flip の everything.php には、PHP リモートファイルインクルージョンの脆弱性が存在します。 | CVE-2007-2140 | 25495 | 7.5 | http://jvndb.jvn.jp/ja/contents/2007/JVNDB-2007-001848.html | View |