CVE-2013-1901: Canonical Ubuntu Linux
Medium severity, CVSS 4.0. EPSS: 3.3% chance of exploitation in the next 30 days.
PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) pg_start_backup or (2) pg_stop_backup functions.
Affected products
- Canonical Ubuntu Linux: version 8.04 only; version 10.04 only; version 11.10 only; version 12.04 only; version 12.10 only
- PostgreSQL PostgreSQL: version 9.2 only; version 9.2.1 only; version 9.2.2 only; version 9.2.3 only; version 9.1 only; version 9.1.1 only; …
Published 2013-04-04. Last modified 2026-06-16.