CVE-2017-15097Link Following in RED HAT Postgresql Init Script

CWE-59Link Following5 documents5 sources
Severity
6.7MEDIUMNVD
CNA6.5
EPSS
0.0%
top 88.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27
Latest updateMay 24

Description

Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages4 packages

Also affects: Enterprise Linux 7.4, 7.5

🔴Vulnerability Details

2
GHSA
GHSA-4fwh-62fj-p4ww: Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL2022-05-24
CVEList
CVE-2017-15097: Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL2018-07-27

📋Vendor Advisories

1
Red Hat
postgresql: Start scripts permit database administrator to modify root-owned files2017-12-07

💬Community

1
Bugzilla
CVE-2017-15097 postgresql: Start scripts permit database administrator to modify root-owned files2017-11-02
CVE-2017-15097 — Link Following in RED | cvebase