CVE-2010-1975

Description

PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove arbitrary parameter settings via a (1) ALTER USER or (2) ALTER DATABASE statement.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.281

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2010-1169,CVE-2010-1170,CVE-2010-1447,CVE-2010-1975 are affected in Postgresql 9.0.0Windows
Vulnerabilities CVE-2010-1975,CVE-2010-1170,CVE-2010-1169 are fixed in PostgreSQL 8.4.4Windows
Vulnerabilities CVE-2010-1975,CVE-2010-1170,CVE-2010-1169 are fixed in PostgreSQL 8.3.11Windows
Vulnerabilities CVE-2010-1975,CVE-2010-1170,CVE-2010-1169 are fixed in PostgreSQL 8.2.17Windows
Vulnerabilities CVE-2010-1975,CVE-2010-1170,CVE-2010-1169 are fixed in PostgreSQL 8.1.21Windows
Vulnerabilities CVE-2010-1975,CVE-2010-1170,CVE-2010-1169 are fixed in PostgreSQL 8.0.25Windows
Vulnerabilities CVE-2010-1975,CVE-2010-1170,CVE-2010-1169 are fixed in PostgreSQL 7.4.29Windows
Vulnerability CVE-2010-1169,CVE-2010-1170,CVE-2010-1447,CVE-2010-1975 are affected in Postgresql 9.0.0 (For Linux)Linux
Vulnerabilities CVE-2010-1975,CVE-2010-1170,CVE-2010-1169 are fixed in PostgreSQL 8.4.4 (For Linux)Linux
Vulnerabilities CVE-2010-1975,CVE-2010-1170,CVE-2010-1169 are fixed in PostgreSQL 8.3.11 (For Linux)Linux
Vulnerabilities CVE-2010-1975,CVE-2010-1170,CVE-2010-1169 are fixed in PostgreSQL 8.2.17 (For Linux)Linux
Vulnerabilities CVE-2010-1975,CVE-2010-1170,CVE-2010-1169 are fixed in PostgreSQL 8.1.21 (For Linux)Linux
Vulnerabilities CVE-2010-1975,CVE-2010-1170,CVE-2010-1169 are fixed in PostgreSQL 8.0.25 (For Linux)Linux
Vulnerabilities CVE-2010-1975,CVE-2010-1170,CVE-2010-1169 are fixed in PostgreSQL 7.4.29 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234