Short Name |
DB:POSTGRESQL:POSTGRE-DBSEC-BP
|
Severity |
High
|
Recommended |
Yes
|
Recommended Action |
Drop
|
Category |
DB
|
Keywords |
PostgreSQL Database Security Bypass
|
Release Date |
2015/08/27
|
Update Number |
2529
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vsrx-12.1+
|
DB: PostgreSQL Database Security Bypass
This signature detects attempts to exploit a known vulnerability against PostgreSQL. A successful attack can lead to security bypass into the context of the running service.
Extended Description
PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly enforce the ADMIN OPTION restriction, which allows remote authenticated members of a role to add or remove arbitrary users to that role by calling the SET ROLE command before the associated GRANT command.
Affected Products
- postgresql 8.4.1
- postgresql 8.4.10
- postgresql 8.4.11
- postgresql 8.4.12
- postgresql 8.4.13
- postgresql 8.4.14
- postgresql 8.4.15
- postgresql 8.4.16
- postgresql 8.4.17
- postgresql 8.4.18
- postgresql 8.4.19
- postgresql 8.4.2
- postgresql 8.4.3
- postgresql 8.4.4
- postgresql 8.4.5
- postgresql 8.4.6
- postgresql 8.4.7
- postgresql 8.4.8
- postgresql 8.4.9
- postgresql 9.0
- postgresql 9.0.1
- postgresql 9.0.10
- postgresql 9.0.11
- postgresql 9.0.12
- postgresql 9.0.13
- postgresql 9.0.14
- postgresql 9.0.15
- postgresql 9.0.2
- postgresql 9.0.3
- postgresql 9.0.4
- postgresql 9.0.5
- postgresql 9.0.6
- postgresql 9.0.7
- postgresql 9.0.8
- postgresql 9.0.9
- postgresql 9.1
- postgresql 9.1.1
- postgresql 9.1.10
- postgresql 9.1.11
- postgresql 9.1.2
- postgresql 9.1.3
- postgresql 9.1.4
- postgresql 9.1.5
- postgresql 9.1.6
- postgresql 9.1.7
- postgresql 9.1.8
- postgresql 9.1.9
- postgresql 9.2
- postgresql 9.2.1
- postgresql 9.2.2
- postgresql 9.2.3
- postgresql 9.2.4
- postgresql 9.2.5
- postgresql 9.2.6
- postgresql 9.3
- postgresql 9.3.1
- postgresql 9.3.2
References