suse · CVE-2016-5424

Quick triage

Priority: medium Published: 2021-05-30 13:43:49 UTC Updated: 2024-07-27 01:03:25 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-5424 severity moderate: SUSE including 65 source package names (libecpg6-32bit-9.5.4-1.2, libecpg6-9.4.9-0.19.1, …), 119 product×package rows across 20 product lines (SUSE Liberty Linux 7, SUSE Linux Enterprise Desktop 12 SP1, … (20 product lines)): Fixed 117, Known Not Affected 2.

Description:

PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a (1) " (double quote), (2) \ (backslash), (3) carriage return, or (4) newline character in a (a) database or (b) role name that is mishandled during an administrative operation.

cvelogic Threat Intelligence