It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing information from pg_statistic, possibly leaking information. An unprivileged attacker could use this flaw to steal some information from tables they are otherwise not allowed to access.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2017-05-12T19:00:00

Updated: 2018-01-04T19:57:01

Reserved: 2017-04-05T00:00:00


Link: CVE-2017-7484

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2017-05-12T19:29:00.193

Modified: 2018-01-05T02:31:51.277


Link: CVE-2017-7484

JSON object: View

cve-icon Redhat Information

No data.