Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2017-8806

Published: 9 November 2017

The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files.

Notes

AuthorNote
mdeslaur
PostgreSQL will use CVE-2017-12172 for contrib/start-scripts
This is related to CVE-2016-1255

Priority

Medium

Cvss 3 Severity Score

5.5

Score breakdown

Status

Package Release Status
postgresql-common
Launchpad, Ubuntu, Debian
artful
Released (184ubuntu1.1)
trusty
Released (154ubuntu1.1)
upstream Needs triage

xenial
Released (173ubuntu0.1)
zesty
Released (179ubuntu0.1)
Patches:
upstream: https://anonscm.debian.org/cgit/pkg-postgresql/postgresql-common.git/commit/?id=8b4d0a889a8287181c4bdf46462db9b737a6e25d

Severity score breakdown

Parameter Value
Base score 5.5
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact High
Availability impact None
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N