Upstream information

CVE-2014-0067 at MITRE

Description

The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having low severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.6
Vector AV:L/AC:L/Au:N/C:P/I:P/A:P
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
SUSE Bugzilla entries: 864856 [RESOLVED], 872783 [RESOLVED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 12
  • libecpg6 >= 9.3.5-2.3
  • libpq5 >= 9.3.5-2.3
  • libpq5-32bit >= 9.3.5-2.3
  • postgresql93 >= 9.3.5-2.24
Patchnames:
SUSE Linux Enterprise Desktop 12 GA libecpg6
SUSE Linux Enterprise Desktop 12 SP1
  • libecpg6 >= 9.4.5-4.1
  • libpq5 >= 9.4.5-4.1
  • libpq5-32bit >= 9.4.5-4.1
  • postgresql94 >= 9.4.5-4.5
Patchnames:
SUSE Linux Enterprise Desktop 12 SP1 GA libecpg6
SUSE Linux Enterprise Desktop 12 SP2
  • libecpg6 >= 9.4.9-14.1
  • libpq5 >= 9.4.9-14.1
  • libpq5-32bit >= 9.4.9-14.1
  • postgresql94 >= 9.4.9-14.1
Patchnames:
SUSE Linux Enterprise Desktop 12 SP2 GA libecpg6
SUSE Linux Enterprise Desktop 12 SP3
  • libecpg6 >= 9.6.3-2.1
  • libpq5 >= 9.6.3-2.1
  • libpq5-32bit >= 9.6.3-2.1
  • postgresql96 >= 9.6.3-2.4
Patchnames:
SUSE Linux Enterprise Desktop 12 SP3 GA libecpg6
SUSE Linux Enterprise Server 11 SP4
  • libecpg6 >= 9.4.4-0.6.2
  • libpq5 >= 9.4.4-0.6.2
  • libpq5-32bit >= 9.4.4-0.6.2
  • postgresql94 >= 9.4.4-0.6.2
  • postgresql94-contrib >= 9.4.4-0.6.2
  • postgresql94-docs >= 9.4.4-0.6.2
  • postgresql94-server >= 9.4.4-0.6.2
Patchnames:
SUSE Linux Enterprise Server 11 SP4 GA libecpg6
SUSE Linux Enterprise Server 12
  • libecpg6 >= 9.3.5-2.3
  • libpq5 >= 9.3.5-2.3
  • libpq5-32bit >= 9.3.5-2.3
  • postgresql93 >= 9.3.5-2.24
  • postgresql93-contrib >= 9.3.5-2.24
  • postgresql93-docs >= 9.3.5-2.24
  • postgresql93-server >= 9.3.5-2.24
Patchnames:
SUSE Linux Enterprise Server 12 GA libecpg6
SUSE Linux Enterprise Server 12 SP1
  • libecpg6 >= 9.4.5-4.1
  • libpq5 >= 9.4.5-4.1
  • libpq5-32bit >= 9.4.5-4.1
  • postgresql94 >= 9.4.5-4.5
  • postgresql94-contrib >= 9.4.5-4.5
  • postgresql94-docs >= 9.4.5-4.5
  • postgresql94-server >= 9.4.5-4.5
Patchnames:
SUSE Linux Enterprise Server 12 SP1 GA libecpg6
SUSE Linux Enterprise Server 12 SP2
  • libecpg6 >= 9.4.9-14.1
  • libpq5 >= 9.4.9-14.1
  • libpq5-32bit >= 9.4.9-14.1
  • postgresql94 >= 9.4.9-14.1
  • postgresql94-contrib >= 9.4.9-14.1
  • postgresql94-docs >= 9.4.9-14.1
  • postgresql94-server >= 9.4.9-14.1
Patchnames:
SUSE Linux Enterprise Server 12 SP2 GA libecpg6
SUSE Linux Enterprise Server 12 SP3
  • libecpg6 >= 9.6.3-2.1
  • libpq5 >= 9.6.3-2.1
  • libpq5-32bit >= 9.6.3-2.1
  • postgresql96 >= 9.6.3-2.4
  • postgresql96-contrib >= 9.6.3-2.4
  • postgresql96-docs >= 9.6.3-2.4
  • postgresql96-server >= 9.6.3-2.4
Patchnames:
SUSE Linux Enterprise Server 12 SP3 GA libecpg6
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
  • libecpg6 >= 9.4.9-14.1
  • libpq5 >= 9.4.9-14.1
  • postgresql94 >= 9.4.9-14.1
  • postgresql94-contrib >= 9.4.9-14.1
  • postgresql94-docs >= 9.4.9-14.1
  • postgresql94-server >= 9.4.9-14.1
Patchnames:
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 GA libecpg6
SUSE Linux Enterprise Software Development Kit 11 SP4
  • postgresql94-devel >= 9.4.4-0.6.2
Patchnames:
SUSE Linux Enterprise Software Development Kit 11 SP4 GA postgresql94-devel
SUSE Linux Enterprise Software Development Kit 12
  • postgresql93-devel >= 9.3.5-2.3
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 GA postgresql93-devel
SUSE Linux Enterprise Software Development Kit 12 SP1
  • postgresql94-devel >= 9.4.5-4.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP1 GA postgresql94-devel
SUSE Linux Enterprise Software Development Kit 12 SP2
  • postgresql94-devel >= 9.4.9-14.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP2 GA postgresql94-devel
SUSE Linux Enterprise Software Development Kit 12 SP3
  • postgresql96-devel >= 9.6.3-2.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP3 GA postgresql96-devel
SUSE Linux Enterprise Software Development Kit 11 SP3
  • postgresql91-devel >= 9.1.12-0.3.1
Builds
SAT Patch Nr: 8970
SUSE Linux Enterprise Desktop 11 SP3
  • libecpg6 >= 9.1.12-0.3.1
  • libpq5 >= 9.1.12-0.3.1
  • postgresql91 >= 9.1.12-0.3.1
  • postgresql91-docs >= 9.1.12-0.3.1
Builds
SAT Patch Nr: 8970
SUSE Linux Enterprise Desktop 11 SP3
  • libecpg6 >= 9.1.12-0.3.1
  • libpq5 >= 9.1.12-0.3.1
  • libpq5-32bit >= 9.1.12-0.3.1
  • postgresql91 >= 9.1.12-0.3.1
  • postgresql91-docs >= 9.1.12-0.3.1
Builds
SAT Patch Nr: 8970
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP3 for VMware
  • libecpg6 >= 9.1.12-0.3.1
  • libpq5 >= 9.1.12-0.3.1
  • postgresql91 >= 9.1.12-0.3.1
  • postgresql91-contrib >= 9.1.12-0.3.1
  • postgresql91-docs >= 9.1.12-0.3.1
  • postgresql91-server >= 9.1.12-0.3.1
Builds
SAT Patch Nr: 8970
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP3 for VMware
  • libecpg6 >= 9.1.12-0.3.1
  • libpq5 >= 9.1.12-0.3.1
  • libpq5-32bit >= 9.1.12-0.3.1
  • postgresql91 >= 9.1.12-0.3.1
  • postgresql91-contrib >= 9.1.12-0.3.1
  • postgresql91-docs >= 9.1.12-0.3.1
  • postgresql91-server >= 9.1.12-0.3.1
Builds
SAT Patch Nr: 8970
openSUSE 12.3
  • libecpg6 >= 9.2.7-1.12.1
  • libecpg6-32bit >= 9.2.7-1.12.1
  • libecpg6-debuginfo >= 9.2.7-1.12.1
  • libecpg6-debuginfo-32bit >= 9.2.7-1.12.1
  • libpq5 >= 9.2.7-1.12.1
  • libpq5-32bit >= 9.2.7-1.12.1
  • libpq5-debuginfo >= 9.2.7-1.12.1
  • libpq5-debuginfo-32bit >= 9.2.7-1.12.1
  • postgresql92 >= 9.2.7-1.12.1
  • postgresql92-contrib >= 9.2.7-1.12.1
  • postgresql92-contrib-debuginfo >= 9.2.7-1.12.1
  • postgresql92-debuginfo >= 9.2.7-1.12.1
  • postgresql92-debugsource >= 9.2.7-1.12.1
  • postgresql92-devel >= 9.2.7-1.12.1
  • postgresql92-devel-debuginfo >= 9.2.7-1.12.1
  • postgresql92-docs >= 9.2.7-1.12.1
  • postgresql92-libs >= 9.2.7-1.12.1
  • postgresql92-libs-debugsource >= 9.2.7-1.12.1
  • postgresql92-plperl >= 9.2.7-1.12.1
  • postgresql92-plperl-debuginfo >= 9.2.7-1.12.1
  • postgresql92-plpython >= 9.2.7-1.12.1
  • postgresql92-plpython-debuginfo >= 9.2.7-1.12.1
  • postgresql92-pltcl >= 9.2.7-1.12.1
  • postgresql92-pltcl-debuginfo >= 9.2.7-1.12.1
  • postgresql92-server >= 9.2.7-1.12.1
  • postgresql92-server-debuginfo >= 9.2.7-1.12.1
Patchnames:
openSUSE-2014-192
openSUSE 13.1
  • libecpg6 >= 9.2.7-4.4.1
  • libecpg6-32bit >= 9.2.7-4.4.1
  • libecpg6-debuginfo >= 9.2.7-4.4.1
  • libecpg6-debuginfo-32bit >= 9.2.7-4.4.1
  • libpq5 >= 9.2.7-4.4.1
  • libpq5-32bit >= 9.2.7-4.4.1
  • libpq5-debuginfo >= 9.2.7-4.4.1
  • libpq5-debuginfo-32bit >= 9.2.7-4.4.1
  • postgresql92 >= 9.2.7-4.4.1
  • postgresql92-contrib >= 9.2.7-4.4.1
  • postgresql92-contrib-debuginfo >= 9.2.7-4.4.1
  • postgresql92-debuginfo >= 9.2.7-4.4.1
  • postgresql92-debugsource >= 9.2.7-4.4.1
  • postgresql92-devel >= 9.2.7-4.4.1
  • postgresql92-devel-debuginfo >= 9.2.7-4.4.1
  • postgresql92-docs >= 9.2.7-4.4.1
  • postgresql92-libs >= 9.2.7-4.4.1
  • postgresql92-libs-debugsource >= 9.2.7-4.4.1
  • postgresql92-plperl >= 9.2.7-4.4.1
  • postgresql92-plperl-debuginfo >= 9.2.7-4.4.1
  • postgresql92-plpython >= 9.2.7-4.4.1
  • postgresql92-plpython-debuginfo >= 9.2.7-4.4.1
  • postgresql92-pltcl >= 9.2.7-4.4.1
  • postgresql92-pltcl-debuginfo >= 9.2.7-4.4.1
  • postgresql92-server >= 9.2.7-4.4.1
  • postgresql92-server-debuginfo >= 9.2.7-4.4.1
Patchnames:
openSUSE-2014-192
openSUSE Leap 15.0
  • postgresql96 >= 9.6.8-lp150.1.2
  • postgresql96-server >= 9.6.8-lp150.1.2
Patchnames:
openSUSE Leap 15.0 GA postgresql96
openSUSE Leap 42.1
  • libecpg6 >= 9.4.5-1.1
  • libpq5 >= 9.4.5-1.1
  • libpq5-32bit >= 9.4.5-1.1
  • postgresql94 >= 9.4.5-1.2
  • postgresql94-contrib >= 9.4.5-1.2
  • postgresql94-devel >= 9.4.5-1.1
  • postgresql94-docs >= 9.4.5-1.2
  • postgresql94-server >= 9.4.5-1.2
Patchnames:
openSUSE Leap 42.1 GA libecpg6
openSUSE Leap 42.2
  • libecpg6 >= 9.4.9-8.1
  • libpq5 >= 9.4.9-8.1
  • postgresql93-docs >= 9.3.11-4.1
  • postgresql94 >= 9.4.9-8.1
  • postgresql94-contrib >= 9.4.9-8.1
  • postgresql94-devel >= 9.4.9-8.1
  • postgresql94-docs >= 9.4.9-8.1
  • postgresql94-server >= 9.4.9-8.1
Patchnames:
openSUSE Leap 42.2 GA libecpg6
openSUSE Leap 42.2 GA postgresql93-docs
openSUSE Leap 42.3
  • libecpg6 >= 9.6.3-3.1
  • libpq5 >= 9.6.3-3.1
  • postgresql93-docs >= 9.3.17-6.1
  • postgresql94-docs >= 9.4.12-10.1
  • postgresql95-docs >= 9.5.7-1.8
  • postgresql96 >= 9.6.3-3.1
  • postgresql96-contrib >= 9.6.3-3.1
  • postgresql96-devel >= 9.6.3-3.1
  • postgresql96-docs >= 9.6.3-3.1
  • postgresql96-server >= 9.6.3-3.1
Patchnames:
openSUSE Leap 42.3 GA libecpg6
openSUSE Leap 42.3 GA postgresql93-docs
openSUSE Leap 42.3 GA postgresql94-docs
openSUSE Leap 42.3 GA postgresql95-docs
openSUSE Tumbleweed
  • libecpg6 >= 9.5.4-1.2
  • libecpg6-32bit >= 9.5.4-1.2
  • libpq5 >= 9.5.4-1.2
  • libpq5-32bit >= 9.5.4-1.2
  • postgresql93 >= 9.3.15-1.1
  • postgresql93-contrib >= 9.3.15-1.1
  • postgresql93-devel >= 9.3.15-1.1
  • postgresql93-docs >= 9.3.15-1.1
  • postgresql93-plperl >= 9.3.15-1.1
  • postgresql93-plpython >= 9.3.15-1.1
  • postgresql93-pltcl >= 9.3.15-1.1
  • postgresql93-server >= 9.3.15-1.1
  • postgresql93-test >= 9.3.15-1.1
  • postgresql94 >= 9.4.10-1.1
  • postgresql94-contrib >= 9.4.10-1.1
  • postgresql94-devel >= 9.4.10-1.1
  • postgresql94-docs >= 9.4.10-1.1
  • postgresql94-plperl >= 9.4.10-1.1
  • postgresql94-plpython >= 9.4.10-1.1
  • postgresql94-pltcl >= 9.4.10-1.1
  • postgresql94-server >= 9.4.10-1.1
  • postgresql94-test >= 9.4.10-1.1
  • postgresql95 >= 9.5.4-1.2
  • postgresql95-contrib >= 9.5.4-1.2
  • postgresql95-devel >= 9.5.4-1.2
  • postgresql95-docs >= 9.5.4-1.2
  • postgresql95-plperl >= 9.5.4-1.2
  • postgresql95-plpython >= 9.5.4-1.2
  • postgresql95-pltcl >= 9.5.4-1.2
  • postgresql95-server >= 9.5.4-1.2
  • postgresql95-test >= 9.5.4-1.2
Patchnames:
openSUSE Tumbleweed GA libecpg6-32bit
openSUSE Tumbleweed GA postgresql93
openSUSE Tumbleweed GA postgresql94