CVE-2007-2138

NameCVE-2007-2138
DescriptionUntrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner, related to "search_path settings."
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1309-1, DSA-1311-1
NVD severitymedium (attack range: remote)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
postgresqlsourcesarge7.4.7-6sarge5mediumDSA-1311-1
postgresql-7.4source(unstable)1:7.4.17-1medium
postgresql-7.4sourceetch1:7.4.17-0etch1mediumDSA-1311-1
postgresql-8.1source(unstable)8.1.9-1medium
postgresql-8.1sourceetch8.1.9-0etch1mediumDSA-1309-1
postgresql-8.2source(unstable)8.2.4-1medium

Search for package or bug name: Reporting problems