CVE-2013-1901

PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) pg_start_backup or (2) pg_stop_backup functions.

Date published : 2013-04-04

http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html

http://lists.apple.com/archives/security-announce/2013/Sep/msg00004.html