UBUNTU-CVE-2014-0060

Source
https://ubuntu.com/security/CVE-2014-0060
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-0060.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2014-0060
Upstream
  • CVE-2014-0060
Related
  • USN-2120-1
Published
2014-02-21T00:00:00Z
Modified
2026-04-22T09:26:41.573490Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly enforce the ADMIN OPTION restriction, which allows remote authenticated members of a role to add or remove arbitrary users to that role by calling the SET ROLE command before the associated GRANT command.

References

Affected packages

Ubuntu:14.04:LTS / postgresql-9.1

Package

Name
postgresql-9.1
Purl
pkg:deb/ubuntu/postgresql-9.1@9.1.12-1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.1.12-1

Affected versions

9.*
9.1.10-1
9.1.10-1bzr1
9.1.11-1
9.1.11-2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "9.1.12-1",
            "binary_name": "postgresql-plperl-9.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-0060.json"

Ubuntu:14.04:LTS / postgresql-9.3

Package

Name
postgresql-9.3
Purl
pkg:deb/ubuntu/postgresql-9.3@9.3.3-1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.3.3-1

Affected versions

9.*
9.3.1-1
9.3.2-1
9.3.2-1ubuntu1
9.3.2-1ubuntu2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "9.3.3-1",
            "binary_name": "libecpg-compat3"
        },
        {
            "binary_version": "9.3.3-1",
            "binary_name": "libecpg6"
        },
        {
            "binary_version": "9.3.3-1",
            "binary_name": "libpgtypes3"
        },
        {
            "binary_version": "9.3.3-1",
            "binary_name": "libpq5"
        },
        {
            "binary_version": "9.3.3-1",
            "binary_name": "postgresql-9.3"
        },
        {
            "binary_version": "9.3.3-1",
            "binary_name": "postgresql-client-9.3"
        },
        {
            "binary_version": "9.3.3-1",
            "binary_name": "postgresql-contrib-9.3"
        },
        {
            "binary_version": "9.3.3-1",
            "binary_name": "postgresql-doc-9.3"
        },
        {
            "binary_version": "9.3.3-1",
            "binary_name": "postgresql-plperl-9.3"
        },
        {
            "binary_version": "9.3.3-1",
            "binary_name": "postgresql-plpython-9.3"
        },
        {
            "binary_version": "9.3.3-1",
            "binary_name": "postgresql-plpython3-9.3"
        },
        {
            "binary_version": "9.3.3-1",
            "binary_name": "postgresql-pltcl-9.3"
        },
        {
            "binary_version": "9.3.3-1",
            "binary_name": "postgresql-server-dev-9.3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-0060.json"