PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade postgresqlUpgrade ja-postgresqlUpgrade postgresql-server | Dec 10, 2025 | Aug 13, 2006 |
| Gentoo Linux | — | Upgrade dev-db/postgresql. | Oct 30, 2017 | May 2, 2005 |
| Suse | — | Upgrade postgresql-libs-x86Upgrade postgresql-contribUpgrade postgresql-develUpgrade postgresql-libs-32bitUpgrade postgresql-libs-64bitUpgrade postgresql-libsUpgrade postgresql-plUpgrade postgresql-serverUpgrade postgresqlUpgrade postgresql-docs | Feb 17, 2015 | May 2, 2005 |
| Ubuntu | — | Upgrade postgresql | Nov 8, 2024 | May 2, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub