Описание
PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulting in a denial of service.
An authorization flaw was found in the way PostgreSQL handled large objects. A remote, authenticated attacker with no privileges on a large object could potentially use this flaw to overwrite the entire content of the object, thus resulting in denial of service.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
CloudForms Management Engine 5 | rh-postgresql94-postgresql | Not affected | ||
CloudForms Management Engine 5 | rh-postgresql95-postgresql | Not affected | ||
Red Hat Enterprise Linux 5 | postgresql | Not affected | ||
Red Hat Enterprise Linux 5 | postgresql84 | Not affected | ||
Red Hat Enterprise Linux 6 | postgresql | Not affected | ||
Red Hat Enterprise Linux 7 | postgresql | Not affected | ||
Red Hat Satellite 5 | postgresql92-postgresql | Not affected | ||
Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-postgresql95-postgresql | Fixed | RHSA-2017:2677 | 12.09.2017 |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-postgresql94-postgresql | Fixed | RHSA-2017:2678 | 12.09.2017 |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-postgresql95-postgresql | Fixed | RHSA-2017:2677 | 12.09.2017 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulting in a denial of service.
PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulting in a denial of service.
PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to a ...
PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulting in a denial of service.
Уязвимость системы управления базами данных PostgreSQL, вызванная недостатками авторизации, позволяющая нарушителю вызвать отказ системы
EPSS
5.4 Medium
CVSS3