postgresql: Vulnerability during "make check"
Published Mar 28, 2014
4.6
MEDIUMCVSS 2.0
EPSS 0.48%
Description
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.
Affected products
No data.
Configuration 1
- 10.10.4
- 5.0.3
Configuration 2
- ≤ 8.4.19
- 8.4.1
- 8.4.2
- 8.4.3
- 8.4.4
- 8.4.5
- 8.4.6
- 8.4.7
- 8.4.8
- 8.4.9
- 8.4.10
- 8.4.11
- 8.4.12
- 8.4.13
- 8.4.14
- 8.4.15
- 8.4.16
- 8.4.17
- 8.4.18
- 9.0
- 9.0.1
- 9.0.2
- 9.0.3
- 9.0.4
- 9.0.5
- 9.0.6
- 9.0.7
- 9.0.8
- 9.0.9
- 9.0.10
- 9.0.11
- 9.0.12
- 9.0.13
- 9.0.14
- 9.0.15
- 9.1
- 9.1.1
- 9.1.2
- 9.1.3
- 9.1.4
- 9.1.5
- 9.1.6
- 9.1.7
- 9.1.8
- 9.1.9
- 9.1.10
- 9.1.11
- 9.2
- 9.2.1
- 9.2.2
- 9.2.3
- 9.2.4
- 9.2.5
- 9.2.6
- 9.3
- 9.3.1
- 9.3.2
No data.
Red Hat Enterprise Linux 5
postgresql
Will not fix
Red Hat Enterprise Linux 5
postgresql84
Will not fix
Red Hat Enterprise Linux 6
postgresql
Will not fix
Red Hat Software Collections
postgresql92-postgresql
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | postgresql | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | postgresql84 | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | postgresql | Will not fix | n/a |
| Red Hat Software Collections | postgresql92-postgresql | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect postgresql packages as shipped with Red Hat Enterprise Linux and Red Hat Software Collections. Refer to bug 1065863 for further details: https://bugzilla.redhat.com/show_bug.cgi?id=1065863
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.48% (0.00484) | 39.43th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.48% (0.00484) | 37.72th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.05% (0.00052) | 13.34th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.28% (0.01282) | 68.34th | v2 (v2022.01.01) |
| Feb 22, 2023 | 1.28% (0.01282) | 68.05th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.28% (0.01282) | 65.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.28% (0.01282) | 41.72th | v2 (v2022.01.01) |
References (15)
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00018.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2014-03/msg00038.html vendor-advisoryx_refsource_SUSE
- http://wiki.postgresql.org/wiki/20140220securityrelease x_refsource_CONFIRMVendor Advisory
- http://www.debian.org/security/2014/dsa-2864 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2014/dsa-2865 vendor-advisoryx_refsource_DEBIAN
- http://www.postgresql.org/about/news/1506/ x_refsource_CONFIRM
- http://www.securityfocus.com/bid/65721 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2014-0067 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1065863 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2014-0067
- https://support.apple.com/HT205219 x_refsource_CONFIRM
- https://support.apple.com/kb/HT205031 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2014-0067
Change history (0)
No recorded changes yet.