{"id":"CVE-2017-7484","details":"It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing information from pg_statistic, possibly leaking information. An unprivileged attacker could use this flaw to steal some information from tables they are otherwise not allowed to access.","modified":"2026-03-15T22:17:52.263830Z","published":"2017-05-12T19:29:00.193Z","related":["MGASA-2017-0230","SUSE-SU-2017:1441-1","SUSE-SU-2017:1690-1","SUSE-SU-2017:1783-1"],"references":[{"type":"WEB","url":"http://www.securitytracker.com/id/1038476"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:2425"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201710-06"},{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-3851"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/98459"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:1677"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:1678"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:1838"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:1983"},{"type":"ADVISORY","url":"https://www.postgresql.org/about/news/1746/"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"9.2.20"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.1"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.2"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.3"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.4"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.5"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.6"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.7"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.8"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.9"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.10"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.11"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.12"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.13"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.14"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.15"}]},{"events":[{"introduced":"0"},{"last_affected":"9.3.16"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.1"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.2"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.3"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.4"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.5"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.6"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.7"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.8"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.9"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.10"}]},{"events":[{"introduced":"0"},{"last_affected":"9.4.11"}]},{"events":[{"introduced":"0"},{"last_affected":"9.5"}]},{"events":[{"introduced":"0"},{"last_affected":"9.5.1"}]},{"events":[{"introduced":"0"},{"last_affected":"9.5.2"}]},{"events":[{"introduced":"0"},{"last_affected":"9.5.3"}]},{"events":[{"introduced":"0"},{"last_affected":"9.5.4"}]},{"events":[{"introduced":"0"},{"last_affected":"9.5.5"}]},{"events":[{"introduced":"0"},{"last_affected":"9.5.6"}]},{"events":[{"introduced":"0"},{"last_affected":"9.6"}]},{"events":[{"introduced":"0"},{"last_affected":"9.6.1"}]},{"events":[{"introduced":"0"},{"last_affected":"9.6.2"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7484.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}