CVE-2016-1255
published 2017-12-05CVE-2016-1255: The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in…
PriorityP339high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.42%
34.1th percentile
The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, in Ubuntu 14.04 LTS before 154ubuntu1.1, in Ubuntu 16.04 LTS before 173ubuntu0.1, in Ubuntu 17.04 before 179ubuntu0.1, and in Ubuntu 17.10 before 184ubuntu1.1 allows local users to gain root privileges via a symlink attack on a logfile in /var/log/postgresql.
Affected
191 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | postgresql-common | < postgresql-common 178 (bookworm) | postgresql-common 178 (bookworm) |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
| debian | postgresql-common | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
postgresql-common vulnerabilities
vendor_ubuntu·2017-11-27·CVSS 7.8
CVE-2016-1255 [HIGH] postgresql-common vulnerabilities
Title: postgresql-common vulnerabilities
Summary: postgresql-common could be made to overwrite files as the administrator.
USN-3476-1 fixed two vulnerabilities in postgresql-common. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Dawid Golunski discovered that the postgresql-common pg_ctlcluster script
incorrectly handled symlinks. A local attacker could possibly use this
issue to escalate privileges. (CVE-2016-1255)
It was discovered that the postgresql-common helper scripts incorrectly
handled symlinks. A local attacker could possibly use this issue to
escalate privileges. (CVE-2017-8806)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
postgresql-common vulnerabilities
vendor_ubuntu·2017-11-09·CVSS 7.8
CVE-2016-1255 [HIGH] postgresql-common vulnerabilities
Title: postgresql-common vulnerabilities
Summary: postgresql-common could be made to overwrite files as the administrator.
Dawid Golunski discovered that the postgresql-common pg_ctlcluster script
incorrectly handled symlinks. A local attacker could possibly use this
issue to escalate privileges. This issue only affected Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-1255)
It was discovered that the postgresql-common helper scripts incorrectly
handled symlinks. A local attacker could possibly use this issue to
escalate privileges. (CVE-2017-8806)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2016-1255: postgresql-common - The pg_ctlcluster script in postgresql-common package in Debian wheezy before 13...
vendor_debian·2016·CVSS 7.8
CVE-2016-1255 [HIGH] CVE-2016-1255: postgresql-common - The pg_ctlcluster script in postgresql-common package in Debian wheezy before 13...
The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, in Ubuntu 14.04 LTS before 154ubuntu1.1, in Ubuntu 16.04 LTS before 173ubuntu0.1, in Ubuntu 17.04 before 179ubuntu0.1, and in Ubuntu 17.10 before 184ubuntu1.1 allows local users to gain root privileges via a symlink attack on a logfile in /var/log/postgresql.
Scope: local
bookworm: resolved (fixed in 178)
bullseye: resolved (fixed in 178)
forky: resolved (fixed in 178)
sid: resolved (fixed in 178)
trixie: resolved (fixed in 178)
GHSA
GHSA-67hr-wg4g-mjjv: The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable befor
ghsa_unreviewed·2022-05-17
CVE-2016-1255 [HIGH] CWE-59 GHSA-67hr-wg4g-mjjv: The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable befor
The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, in Ubuntu 14.04 LTS before 154ubuntu1.1, in Ubuntu 16.04 LTS before 173ubuntu0.1, in Ubuntu 17.04 before 179ubuntu0.1, and in Ubuntu 17.10 before 184ubuntu1.1 allows local users to gain root privileges via a symlink attack on a logfile in /var/log/postgresql.
OSV
CVE-2016-1255: The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable befor
osv·2017-12-05·CVSS 7.8
CVE-2016-1255 [HIGH] CVE-2016-1255: The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable befor
The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, in Ubuntu 14.04 LTS before 154ubuntu1.1, in Ubuntu 16.04 LTS before 173ubuntu0.1, in Ubuntu 17.04 before 179ubuntu0.1, and in Ubuntu 17.10 before 184ubuntu1.1 allows local users to gain root privileges via a symlink attack on a logfile in /var/log/postgresql.
OSV
postgresql-common vulnerabilities
osv·2017-11-09·CVSS 7.8
CVE-2016-1255 [HIGH] postgresql-common vulnerabilities
postgresql-common vulnerabilities
Dawid Golunski discovered that the postgresql-common pg_ctlcluster script
incorrectly handled symlinks. A local attacker could possibly use this
issue to escalate privileges. This issue only affected Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-1255)
It was discovered that the postgresql-common helper scripts incorrectly
handled symlinks. A local attacker could possibly use this issue to
escalate privileges. (CVE-2017-8806)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.ubuntu.com/usn/USN-3476-1http://www.ubuntu.com/usn/USN-3476-2https://anonscm.debian.org/cgit/pkg-postgresql/postgresql-common.git/commit/?id=c8989206ec360f199400c74f129f7b4cb878c1eehttps://lists.debian.org/debian-lts-announce/2017/01/msg00002.htmlhttp://www.ubuntu.com/usn/USN-3476-1http://www.ubuntu.com/usn/USN-3476-2https://anonscm.debian.org/cgit/pkg-postgresql/postgresql-common.git/commit/?id=c8989206ec360f199400c74f129f7b4cb878c1eehttps://lists.debian.org/debian-lts-announce/2017/01/msg00002.html
2017-12-05
Published