ALT-PU-2018-1766-1
Package postgresql9.6 updated to version 9.6.9-alt0.M70P.1 for branch p7 in task 205931.
Closed vulnerabilities
Published: 2018-05-10
BDU:2019-04242
Уязвимость функции pg_catalog.pg_logfile_rotate() модуля adminpack системы управления базами данных PostgreSQL, позволяющая нарушителю оказать воздействие на целостность защищаемой информации или вызвать отказ в обслуживании
Severity: CRITICAL (9.1)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Severity: CRITICAL (9.4)
Vector: AV:N/AC:L/Au:N/C:N/I:C/A:C
References:
Published: 2018-05-10
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-1115
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.
Severity: MEDIUM (6.4)
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P
Severity: CRITICAL (9.1)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
References:
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.html
- http://www.securityfocus.com/bid/104285
- https://access.redhat.com/errata/RHSA-2018:2565
- https://access.redhat.com/errata/RHSA-2018:2566
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1115
- https://git.postgresql.org/gitweb/?p=postgresql.git%3Ba=commitdiff%3Bh=7b34740
- https://security.gentoo.org/glsa/201810-08
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.html
- http://www.securityfocus.com/bid/104285
- https://access.redhat.com/errata/RHSA-2018:2565
- https://access.redhat.com/errata/RHSA-2018:2566
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1115
- https://git.postgresql.org/gitweb/?p=postgresql.git%3Ba=commitdiff%3Bh=7b34740
- https://security.gentoo.org/glsa/201810-08