CVE-2017-8806
Published: 9 November 2017
The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files.
Notes
Author | Note |
---|---|
mdeslaur | PostgreSQL will use CVE-2017-12172 for contrib/start-scripts This is related to CVE-2016-1255 |
Priority
Status
Package | Release | Status |
---|---|---|
postgresql-common Launchpad, Ubuntu, Debian |
artful |
Released
(184ubuntu1.1)
|
trusty |
Released
(154ubuntu1.1)
|
|
upstream |
Needs triage
|
|
xenial |
Released
(173ubuntu0.1)
|
|
zesty |
Released
(179ubuntu0.1)
|
|
Patches: upstream: https://anonscm.debian.org/cgit/pkg-postgresql/postgresql-common.git/commit/?id=8b4d0a889a8287181c4bdf46462db9b737a6e25d |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 5.5 |
Attack vector | Local |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | High |
Availability impact | None |
Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |