Executive Summary
| Informations | |||
|---|---|---|---|
| Name | CVE-2009-3230 | First vendor Publication | 2009-09-17 |
| Vendor | Cve | Last vendor Modification | 2010-08-21 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:S/C:P/I:P/A:P) | |||
|---|---|---|---|
| Cvss Base Score | 6.5 | Attack Range | Network |
| Cvss Impact Score | 6.4 | Attack Complexity | Low |
| Cvss Expoit Score | 8 | Authentification | Requires single instance |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7.4.26 does not use the appropriate privileges for the (1) RESET ROLE and (2) RESET SESSION AUTHORIZATION operations, which allows remote authenticated users to gain privileges. NOTE: this is due to an incomplete fix for CVE-2007-6600. |
Original Source
| Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3230 |
CAPEC : Common Attack Pattern Enumeration & Classification
| id | Name |
|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
| CAPEC-13 | Subverting Environment Variable Values |
| CAPEC-17 | Accessing, Modifying or Executing Executable Files |
| CAPEC-39 | Manipulating Opaque Client-based Data Tokens |
| CAPEC-45 | Buffer Overflow via Symbolic Links |
| CAPEC-51 | Poison Web Service Registry |
| CAPEC-59 | Session Credential Falsification through Prediction |
| CAPEC-60 | Reusing Session IDs (aka Session Replay) |
| CAPEC-76 | Manipulating Input to File System Calls |
| CAPEC-77 | Manipulating User-Controlled Variables |
| CAPEC-87 | Forceful Browsing |
| CAPEC-104 | Cross Zone Scripting |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-285 | Improper Access Control (Authorization) |
| CWE-264 | Permissions, Privileges, and Access Controls |
OVAL Definitions
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 57901 | PostgreSQL RESET SESSION AUTHORIZATION Remote Privilege Escalation |
Internal Sources (Detail)
Alert History
| Date | Informations |
|---|---|
| 2013-05-10 23:57:26 |
|

CVE-2009-3230
(High)
(Medium)








