TROYANOSYVIRUS
Back to CVEs

CVE-2016-0766

HIGH
8.8

Description

PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privileges via unspecified vectors.

CVE Details

CVSS v3.1 Score8.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published2/17/2016
Last Modified4/12/2025
Sourcenvd
Honeypot Sightings0

Affected Products

canonical:ubuntu_linuxdebian:debian_linuxpostgresql:postgresql

Weaknesses (CWE)

CWE-264

References

http://www.debian.org/security/2016/dsa-3475(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2016/dsa-3476(af854a3a-2127-422b-91ae-364da2661108)
http://www.postgresql.org/about/news/1644/(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/83184(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1035005(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-2894-1(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/201701-33(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.