High severity7.1NVD Advisory· Published Dec 9, 2016· Updated May 6, 2026
CVE-2016-5424
CVE-2016-5424
Description
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a (1) " (double quote), (2) \ (backslash), (3) carriage return, or (4) newline character in a (a) database or (b) role name that is mishandled during an administrative operation.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- www.postgresql.org/about/news/1688/nvdPatchThird Party AdvisoryVDB Entry
- www.debian.org/security/2016/dsa-3646nvdThird Party Advisory
- www.securityfocus.com/bid/92435nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1036617nvdThird Party AdvisoryVDB Entry
- www.postgresql.org/docs/current/static/release-9-1-23.htmlnvdRelease NotesVendor Advisory
- www.postgresql.org/docs/current/static/release-9-2-18.htmlnvdRelease NotesVendor Advisory
- www.postgresql.org/docs/current/static/release-9-3-14.htmlnvdRelease NotesVendor Advisory
- www.postgresql.org/docs/current/static/release-9-4-9.htmlnvdRelease NotesVendor Advisory
- www.postgresql.org/docs/current/static/release-9-5-4.htmlnvdRelease NotesVendor Advisory
- rhn.redhat.com/errata/RHSA-2016-1781.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-1820.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-1821.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-2606.htmlnvd
- access.redhat.com/errata/RHSA-2017:2425nvd
- security.gentoo.org/glsa/201701-33nvd
News mentions
0No linked articles in our index yet.