CVE-2016-5424

Exceptional database and role names could enable escalation to superuser

Version Information

Affected Version Fixed In Fix Published
9.5 9.5.4 2016-08-11
9.4 9.4.9 2016-08-11
9.3 9.3.14 2016-08-11
9.2 9.2.18 2016-08-11
9.1 9.1.23 2016-08-11

For more information about PostgreSQL versioning, please visit the versioning page.

CVSS 3.0

Overall Score 8.5
Component client
Vector AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Reporting Security Vulnerabilities

If you wish to report a new security vulnerability in PostgreSQL, please send an email to security@postgresql.org.

For reporting non-security bugs, please see the Report a Bug page.