PublicDateAtUSN: 2014-02-21 Candidate: CVE-2014-0062 PublicDate: 2014-03-31 14:58:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0062 http://wiki.postgresql.org/wiki/20140220securityrelease https://ubuntu.com/security/notices/USN-2120-1 Description: Race condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE commands in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allows remote authenticated users to create an unauthorized index or read portions of unauthorized tables by creating or deleting a table with the same name during the timing window. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/postgresql-9.3/+bug/1282677 Priority: medium Discovered-by: Andres Freund Assigned-to: CVSS: Patches_postgresql-9.3: upstream_postgresql-9.3: released (9.3.3) lucid_postgresql-9.3: DNE precise_postgresql-9.3: DNE quantal_postgresql-9.3: DNE saucy_postgresql-9.3: DNE trusty_postgresql-9.3: released (9.3.3-1) trusty/esm_postgresql-9.3: released (9.3.3-1) utopic_postgresql-9.3: DNE devel_postgresql-9.3: DNE Patches_postgresql-9.1: upstream_postgresql-9.1: released (9.1.12) lucid_postgresql-9.1: DNE precise_postgresql-9.1: released (9.1.12-0ubuntu0.12.04) quantal_postgresql-9.1: released (9.1.12-0ubuntu0.12.10) saucy_postgresql-9.1: released (9.1.12-0ubuntu0.13.10) trusty_postgresql-9.1: released (9.1.12-1) trusty/esm_postgresql-9.1: DNE (trusty was released [9.1.12-1]) utopic_postgresql-9.1: DNE devel_postgresql-9.1: DNE Patches_postgresql-8.4: upstream_postgresql-8.4: released (8.4.20) lucid_postgresql-8.4: released (8.4.20-0ubuntu010.04) precise_postgresql-8.4: released (8.4.22-0ubuntu0.12.04) quantal_postgresql-8.4: DNE saucy_postgresql-8.4: DNE trusty_postgresql-8.4: DNE trusty/esm_postgresql-8.4: DNE utopic_postgresql-8.4: DNE devel_postgresql-8.4: DNE