PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) pg_start_backup or (2) pg_stop_backup functions.
| Software | From | Fixed in |
|---|---|---|
| postgresql / postgresql | 9.2.1 | 9.2.1.x |
| postgresql / postgresql | 9.2.3 | 9.2.3.x |
| postgresql / postgresql | 9.2 | 9.2.x |
| postgresql / postgresql | 9.2.2 | 9.2.2.x |
| postgresql / postgresql | 9.1.4 | 9.1.4.x |
| postgresql / postgresql | 9.1 | 9.1.x |
| postgresql / postgresql | 9.1.5 | 9.1.5.x |
| postgresql / postgresql | 9.1.8 | 9.1.8.x |
| postgresql / postgresql | 9.1.2 | 9.1.2.x |
| postgresql / postgresql | 9.1.6 | 9.1.6.x |
| postgresql / postgresql | 9.1.7 | 9.1.7.x |
| postgresql / postgresql | 9.1.3 | 9.1.3.x |
| postgresql / postgresql | 9.1.1 | 9.1.1.x |
| canonical / ubuntu_linux | 8.04 | 8.04.x |
| canonical / ubuntu_linux | 11.10 | 11.10.x |
| canonical / ubuntu_linux | 12.10 | 12.10.x |
| canonical / ubuntu_linux | 12.04 | 12.04.x |
| canonical / ubuntu_linux | 10.04 | 10.04.x |