CVE-2012-0866
Estado: ModificadaMedia (6.5)—
CREATE TRIGGER in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 does not properly check the execute permission for trigger functions marked SECURITY DEFINER, which allows remote authenticated users to execute otherwise restricted triggers on arbitrary data by installing the trigger on an attacker-owned table.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.62%
- Percentil entre todas las CVEs puntuadas: 89
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
- http://lists.opensuse.org/opensuse-updates/2012-09/msg00060.html
- http://rhn.redhat.com/errata/RHSA-2012-0677.html
- http://rhn.redhat.com/errata/RHSA-2012-0678.html
- http://secunia.com/advisories/49272
- http://secunia.com/advisories/49273
- http://www.debian.org/security/2012/dsa-2418
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:026
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:027
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:092
- http://www.postgresql.org/about/news/1377/
- http://www.postgresql.org/docs/8.3/static/release-8-3-18.html
- http://www.postgresql.org/docs/8.4/static/release-8-4-11.html
- http://www.postgresql.org/docs/9.0/static/release-9-0-7.html
- http://www.postgresql.org/docs/9.1/static/release-9-1-3.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
- http://lists.opensuse.org/opensuse-updates/2012-09/msg00060.html
- http://rhn.redhat.com/errata/RHSA-2012-0677.html
- http://rhn.redhat.com/errata/RHSA-2012-0678.html
- http://secunia.com/advisories/49272
- http://secunia.com/advisories/49273
- http://www.debian.org/security/2012/dsa-2418
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:026
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:027
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:092
- http://www.postgresql.org/about/news/1377/
- http://www.postgresql.org/docs/8.3/static/release-8-3-18.html
- http://www.postgresql.org/docs/8.4/static/release-8-4-11.html
- http://www.postgresql.org/docs/9.0/static/release-9-0-7.html
- http://www.postgresql.org/docs/9.1/static/release-9-1-3.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-0866",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-07-18T23:55:01.747",
"references": [
{
"url": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705",
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2012-09/msg00060.html",
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2012-0677.html",
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2012-0678.html",
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/49272",
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/49273",
"source": "secalert@redhat.com"
},
{
"url": "http://www.debian.org/security/2012/dsa-2418",
"source": "secalert@redhat.com"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2012:026",
"source": "secalert@redhat.com"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2012:027",
"source": "secalert@redhat.com"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2012:092",
"source": "secalert@redhat.com"
},
{
"url": "http://www.postgresql.org/about/news/1377/",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.postgresql.org/docs/8.3/static/release-8-3-18.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.postgresql.org/docs/8.4/static/release-8-4-11.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.postgresql.org/docs/9.0/static/release-9-0-7.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.postgresql.org/docs/9.1/static/release-9-1-3.html",
"source": "secalert@redhat.com"
},
{
"url": "http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2012-09/msg00060.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2012-0677.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2012-0678.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/49272",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/49273",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2012/dsa-2418",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2012:026",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2012:027",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2012:092",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.postgresql.org/about/news/1377/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.postgresql.org/docs/8.3/static/release-8-3-18.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.postgresql.org/docs/8.4/static/release-8-4-11.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.postgresql.org/docs/9.0/static/release-9-0-7.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.postgresql.org/docs/9.1/static/release-9-1-3.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CREATE TRIGGER in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 does not properly check the execute permission for trigger functions marked SECURITY DEFINER, which allows remote authenticated users to execute otherwise restricted triggers on arbitrary data by installing the trigger on an attacker-owned table."
},
{
"lang": "es",
"value": "CREATE TRIGGER en PostgreSQL v8.3.x antes de v8.3.18, v8.4.x antes de v8.4.11, v9.0.x antes de v9.0.7 y v9.1.x antes v9.1.3, no comprueba correctamente el permiso de ejecución de las funciones de disparo marcados como SECURITY DEFINER, lo que permite a usuarios autenticados remotamente ejecutar los disparadores restringidos en datos arbitrarios mediante la instalación del disparador en una tabla propiedad del atacante."
}
],
"lastModified": "2026-06-16T23:38:24.880",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A2A705DF-3654-427F-8B11-62DB0B6C9813"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "05AD5D33-86F4-4BFF-BA84-02AA1347BEEB"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02FDCF30-D0F7-48AA-9633-9CC060495F47"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "788975F6-B3F1-4C21-B963-6BA59F14B71C"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E6713D96-338B-4467-9F05-3153997F62E2"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "01EB1A77-92AD-47FB-8290-D05C9B6C19C4"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "74857259-30C7-422D-A24D-BE1E33F09466"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CD80066B-787E-496B-88FD-F0AE291468C5"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88C9F0AB-A125-4DCD-A02B-E04D4D95FB5D"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8FF13F89-F4C3-43EC-A36A-2F9283E923B8"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F2631F09-73DD-4A28-8082-3939D89DDBE0"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "82DDE9E7-EBF9-452B-8380-F9E87CF30ACA"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4BAE68CF-198D-4F01-92F3-4DED7E50ACA6"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EF798CBC-C8BB-4F88-A927-B385A0DD8F19"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BF8F568F-7D23-4553-95C5-C7C6B6584EB7"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A1DB64EA-DE7B-4CA4-8121-90612409152D"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A932403-9187-471B-BE65-4B6907D57D1B"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.3.17:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5CC6D76B-EF54-4F03-84BB-4CEAE31C4FFD"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8F30CA60-0A82-45CD-8044-CE245393593D"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5C991F71-1E27-47A6-97DC-424FC3EF6011"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5740C7AA-1772-41D8-9851-3E3669CD8521"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "970338CD-A680-4DD0-BD27-459B0DDA4002"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A99C579D-44C0-40A4-A4EB-CBCF40D0C2FA"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3E9E57FA-5EAE-4698-992D-146C6310E0B8"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C66CDEC1-FB2E-49B7-A8BE-38E43C8ED652"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "87DF2937-9C51-4768-BAB1-901BCA636ADD"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "515C0ECD-2D95-4B6E-8E2F-DAF94E4A310F"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EA0EB754-7A71-40FA-9EAD-44914EB758C3"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:8.4.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1089D316-D5A3-4F2D-9E52-57FD626A1D06"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DD4DE67-9E3C-4F79-8AAB-344C1C46C618"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CCB718D2-97AA-4D61-AA4B-2216EEF55F67"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "605C06BF-54A0-40F8-A01E-8641B4A83035"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1F1F5B75-78D5-408E-8148-CA23DCED9CBB"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88DE8C27-0E0A-4428-B25D-054D4FC6FEA8"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.0.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F609DDE4-0858-4F83-B8E6-7870196E21CB"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "349F02AF-013E-4264-9717-010293A3D6E4"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4796DBEC-FF4F-4749-90D5-AD83D8B5E086"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "79108278-D644-4506-BD9C-F464C6E817B7"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:9.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "10CF0AA0-41CD-4D50-BA7A-BF8846115C95"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}