PostgreSQL Permissions Privileges and Access Controls Vulnerability - CVE-2014-0060 - Vulnerability Database

PostgreSQL Permissions Privileges and Access Controls Vulnerability - CVE-2014-0060

Medium
Reference: CVE-2014-0060
Title: PostgreSQL Permissions Privileges and Access Controls Vulnerability
Overview:

PostgreSQL before 8.4.20 9.0.x before 9.0.16 9.1.x before 9.1.12 9.2.x before 9.2.7 and 9.3.x before 9.3.3 does not properly enforce the ADMIN OPTION restriction which allows remote authenticated members of a role to add or remove arbitrary users to that role by calling the SET ROLE command before the associated GRANT command.