Candidate: CVE-2014-0067 PublicDate: 2014-03-31 14:58:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0067 http://wiki.postgresql.org/wiki/20140220securityrelease Description: The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster. Ubuntu-Description: Notes: Bugs: https://bugs.launchpad.net/ubuntu/+source/postgresql-9.3/+bug/1282677 Priority: low Discovered-by: Noah Misch Assigned-to: CVSS: Patches_postgresql-9.3: upstream_postgresql-9.3: released (9.3.5) lucid_postgresql-9.3: DNE precise_postgresql-9.3: DNE quantal_postgresql-9.3: DNE saucy_postgresql-9.3: DNE trusty_postgresql-9.3: released (9.3.5-0ubuntu0.14.04.1) trusty/esm_postgresql-9.3: released (9.3.5-0ubuntu0.14.04.1) utopic_postgresql-9.3: DNE devel_postgresql-9.3: DNE Patches_postgresql-9.1: upstream_postgresql-9.1: released (9.1.14) lucid_postgresql-9.1: DNE precise_postgresql-9.1: released (9.1.14-0ubuntu0.12.04) quantal_postgresql-9.1: ignored (reached end-of-life) saucy_postgresql-9.1: ignored (reached end-of-life) trusty_postgresql-9.1: released (9.1.15-0ubuntu0.14.04) trusty/esm_postgresql-9.1: DNE (trusty was released [9.1.15-0ubuntu0.14.04]) utopic_postgresql-9.1: DNE devel_postgresql-9.1: DNE Patches_postgresql-8.4: upstream_postgresql-8.4: released (8.4.22) lucid_postgresql-8.4: released (8.4.22-0ubuntu0.10.04) precise_postgresql-8.4: released (8.4.22-0ubuntu0.12.04) quantal_postgresql-8.4: DNE saucy_postgresql-8.4: DNE trusty_postgresql-8.4: DNE trusty/esm_postgresql-8.4: DNE utopic_postgresql-8.4: DNE devel_postgresql-8.4: DNE