Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1115

Опубликовано: 10 мая 2018
Источник: redhat
CVSS3: 4.2
EPSS Низкий

Описание

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.

It was found that pg_catalog.pg_logfile_rotate(), from the adminpack extension, did not follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could use this flaw to force log rotation.

Отчет

This issue does not appear to affect the versions of postgresql as shipped with Red Hat Satellite version 5, CloudForms version 4, Red Hat Single Sign-On 7, and Fuse Service Works 6.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5postgresql94Not affected
CloudForms Management Engine 5rh-postgresql95-postgresqlNot affected
Red Hat Enterprise Linux 5postgresqlNot affected
Red Hat Enterprise Linux 5postgresql84Not affected
Red Hat Enterprise Linux 6postgresqlNot affected
Red Hat Enterprise Linux 7postgresqlNot affected
Red Hat Enterprise Linux 8postgresqlNot affected
Red Hat JBoss Fuse Service Works 6postgresqlNot affected
Red Hat JBoss Operations Network 3postgresqlOut of support scope
Red Hat Mobile Application Platform 4postgresqlNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1573276postgresql: Too-permissive access control list on function pg_logfile_rotate()

EPSS

Процентиль: 60%
0.0041
Низкий

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 7 лет назад

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.

CVSS3: 9.1
nvd
около 7 лет назад

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.

CVSS3: 9.1
debian
около 7 лет назад

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack ...

suse-cvrf
почти 7 лет назад

Recommended update for postgresql95

suse-cvrf
около 7 лет назад

Security update for postgresql96

EPSS

Процентиль: 60%
0.0041
Низкий

4.2 Medium

CVSS3

Уязвимость CVE-2018-1115