CVE-2017-8806
published 2017-11-13CVE-2017-8806: The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.42%
33.8th percentile
The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | postgresql-common | < postgresql-common 188 (bookworm) | postgresql-common 188 (bookworm) |
| debian | postgresql-common | >= 0 < 154ubuntu1.1 | 154ubuntu1.1 |
| debian | postgresql-common | >= 0 < 173ubuntu0.1 | 173ubuntu0.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
postgresql-common vulnerabilities
vendor_ubuntu·2017-11-27·CVSS 7.8
CVE-2016-1255 [HIGH] postgresql-common vulnerabilities
Title: postgresql-common vulnerabilities
Summary: postgresql-common could be made to overwrite files as the administrator.
USN-3476-1 fixed two vulnerabilities in postgresql-common. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Dawid Golunski discovered that the postgresql-common pg_ctlcluster script
incorrectly handled symlinks. A local attacker could possibly use this
issue to escalate privileges. (CVE-2016-1255)
It was discovered that the postgresql-common helper scripts incorrectly
handled symlinks. A local attacker could possibly use this issue to
escalate privileges. (CVE-2017-8806)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
postgresql-common vulnerabilities
vendor_ubuntu·2017-11-09·CVSS 7.8
CVE-2016-1255 [HIGH] postgresql-common vulnerabilities
Title: postgresql-common vulnerabilities
Summary: postgresql-common could be made to overwrite files as the administrator.
Dawid Golunski discovered that the postgresql-common pg_ctlcluster script
incorrectly handled symlinks. A local attacker could possibly use this
issue to escalate privileges. This issue only affected Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-1255)
It was discovered that the postgresql-common helper scripts incorrectly
handled symlinks. A local attacker could possibly use this issue to
escalate privileges. (CVE-2017-8806)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2017-8806: postgresql-common - The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as di...
vendor_debian·2017·CVSS 5.5
CVE-2017-8806 [MEDIUM] CVE-2017-8806: postgresql-common - The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as di...
The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files.
Scope: local
bookworm: resolved (fixed in 188)
bullseye: resolved (fixed in 188)
forky: resolved (fixed in 188)
sid: resolved (fixed in 188)
trixie: resolved (fixed in 188)
GHSA
GHSA-xg92-g8h7-v7r4: The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 fo
ghsa_unreviewed·2022-05-17
CVE-2017-8806 [MEDIUM] CWE-59 GHSA-xg92-g8h7-v7r4: The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 fo
The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files.
OSV
CVE-2017-8806: The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 fo
osv·2017-11-13·CVSS 5.5
CVE-2017-8806 [MEDIUM] CVE-2017-8806: The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 fo
The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files.
OSV
postgresql-common vulnerabilities
osv·2017-11-09·CVSS 7.8
CVE-2016-1255 [HIGH] postgresql-common vulnerabilities
postgresql-common vulnerabilities
Dawid Golunski discovered that the postgresql-common pg_ctlcluster script
incorrectly handled symlinks. A local attacker could possibly use this
issue to escalate privileges. This issue only affected Ubuntu 14.04 LTS and
Ubuntu 16.04 LTS. (CVE-2016-1255)
It was discovered that the postgresql-common helper scripts incorrectly
handled symlinks. A local attacker could possibly use this issue to
escalate privileges. (CVE-2017-8806)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://metadata.ftp-master.debian.org/changelogs/main/p/postgresql-common/postgresql-common_181+deb9u1_changeloghttp://www.securityfocus.com/bid/101810https://usn.ubuntu.com/usn/usn-3476-1/https://www.debian.org/security/2017/dsa-4029http://metadata.ftp-master.debian.org/changelogs/main/p/postgresql-common/postgresql-common_181+deb9u1_changeloghttp://www.securityfocus.com/bid/101810https://usn.ubuntu.com/usn/usn-3476-1/https://www.debian.org/security/2017/dsa-4029
2017-11-13
Published