CVE-2014-0062
Publication date 21 February 2014
Last updated 24 July 2024
Ubuntu priority
Race condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE commands in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allows remote authenticated users to create an unauthorized index or read portions of unauthorized tables by creating or deleting a table with the same name during the timing window.
Status
Package | Ubuntu Release | Status |
---|---|---|
postgresql-8.4 | ||
14.04 LTS trusty | Not in release | |
postgresql-9.1 | ||
14.04 LTS trusty |
Fixed 9.1.12-1
|
|
postgresql-9.3 | ||
14.04 LTS trusty |
Fixed 9.3.3-1
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2120-1
- PostgreSQL vulnerabilities
- 24 February 2014