Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2018:1709-1

Опубликовано: 15 июн. 2018
Источник: suse-cvrf

Описание

Security update for postgresql96

PostgreSQL was updated to 9.6.9 fixing bugs and security issues:

Release notes:

Security issue fixed:

  • CVE-2018-1115: Remove public execute privilege from contrib/adminpack's pg_logfile_rotate() function pg_logfile_rotate() is a deprecated wrapper for the core function pg_rotate_logfile(). When that function was changed to rely on SQL privileges for access control rather than a hard-coded superuser check, pg_logfile_rotate() should have been updated as well, but the need for this was missed. Hence, if adminpack is installed, any user could request a logfile rotation, creating a minor security issue. After installing this update, administrators should update adminpack by performing ALTER EXTENSION adminpack UPDATE in each database in which adminpack is installed. (bsc#1091610)

This update was imported from the SUSE:SLE-12:Update update project.

Список пакетов

openSUSE Leap 42.3
libecpg6-9.6.9-18.1
libecpg6-32bit-9.6.9-18.1
libpq5-9.6.9-18.1
libpq5-32bit-9.6.9-18.1
postgresql96-9.6.9-18.1
postgresql96-contrib-9.6.9-18.1
postgresql96-devel-9.6.9-18.1
postgresql96-docs-9.6.9-18.1
postgresql96-libs-9.6.9-18.1
postgresql96-plperl-9.6.9-18.1
postgresql96-plpython-9.6.9-18.1
postgresql96-pltcl-9.6.9-18.1
postgresql96-server-9.6.9-18.1
postgresql96-test-9.6.9-18.1

Описание

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.


Затронутые продукты
openSUSE Leap 42.3:libecpg6-32bit-9.6.9-18.1
openSUSE Leap 42.3:libecpg6-9.6.9-18.1
openSUSE Leap 42.3:libpq5-32bit-9.6.9-18.1
openSUSE Leap 42.3:libpq5-9.6.9-18.1

Ссылки
Уязвимость openSUSE-SU-2018:1709-1