PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privileges via unspecified vectors.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-0766.json"
[
{
"events": [
{
"introduced": "9.1.0"
},
{
"fixed": "9.1.20"
}
]
},
{
"events": [
{
"introduced": "9.2"
},
{
"fixed": "9.2.15"
}
]
},
{
"events": [
{
"introduced": "9.3"
},
{
"fixed": "9.3.11"
}
]
},
{
"events": [
{
"introduced": "9.4"
},
{
"fixed": "9.4.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
}
]