Описание
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.
Релиз | Статус | Примечание |
---|---|---|
artful | DNE | |
bionic | released | 10.4-0ubuntu0.18.04 |
devel | not-affected | 10.5-1 |
esm-infra-legacy/trusty | DNE | |
esm-infra/bionic | not-affected | 10.4-0ubuntu0.18.04 |
precise/esm | DNE | |
trusty | DNE | |
trusty/esm | DNE | |
upstream | released | 10.4 |
xenial | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
artful | DNE | |
bionic | DNE | |
devel | DNE | |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [code not present]] |
precise/esm | not-affected | code not present |
trusty | not-affected | code not present |
trusty/esm | DNE | trusty was not-affected [code not present] |
upstream | not-affected | code not present |
xenial | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
artful | DNE | |
bionic | DNE | |
devel | DNE | |
esm-infra-legacy/trusty | not-affected | code not present |
precise/esm | DNE | |
trusty | not-affected | code not present |
trusty/esm | not-affected | code not present |
upstream | not-affected | code not present |
xenial | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
artful | DNE | |
bionic | DNE | |
devel | DNE | |
esm-infra-legacy/trusty | DNE | |
esm-infra/xenial | not-affected | code not present |
precise/esm | DNE | |
trusty | DNE | |
trusty/esm | DNE | |
upstream | not-affected | code not present |
xenial | not-affected | code not present |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
artful | ignored | end of life |
bionic | DNE | |
devel | DNE | |
esm-infra-legacy/trusty | DNE | |
precise/esm | DNE | |
trusty | DNE | |
trusty/esm | DNE | |
upstream | released | 9.6.9 |
xenial | DNE |
Показывать по
EPSS
6.4 Medium
CVSS2
9.1 Critical
CVSS3
Связанные уязвимости
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack ...
EPSS
6.4 Medium
CVSS2
9.1 Critical
CVSS3