Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1115

Опубликовано: 10 мая 2018
Источник: debian
EPSS Низкий

Описание

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
postgresql-10fixed10.4-1package
postgresql-9.6removedpackage
postgresql-9.6fixed9.6.9-0+deb9u1stretchpackage
postgresql-9.4removedpackage
postgresql-9.4not-affectedjessiepackage
postgresql-9.1removedpackage
postgresql-9.1not-affectedjessiepackage
postgresql-9.1not-affectedwheezypackage

EPSS

Процентиль: 60%
0.0041
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 7 лет назад

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.

CVSS3: 4.2
redhat
около 7 лет назад

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.

CVSS3: 9.1
nvd
около 7 лет назад

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.

suse-cvrf
почти 7 лет назад

Recommended update for postgresql95

suse-cvrf
около 7 лет назад

Security update for postgresql96

EPSS

Процентиль: 60%
0.0041
Низкий
Уязвимость CVE-2018-1115