CVE-2018-1115
published 2018-05-10CVE-2018-1115: postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than…
PriorityP348critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
4.04%
89.5th percentile
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opensuse | leap | — | — |
| postgresql | postgresql | < 9.6.9 | 9.6.9 |
| postgresql | postgresql | >= 0 < 10.4-r0 | 10.4-r0 |
| postgresql | postgresql | >= 0 < 10.4-r0 | 10.4-r0 |
| postgresql | postgresql | >= 0 < 10.4-r0 | 10.4-r0 |
| postgresql | postgresql | >= 0 < 10.4-r0 | 10.4-r0 |
| postgresql | postgresql | >= 0 < 10.4-r0 | 10.4-r0 |
| postgresql | postgresql | >= 0 < 9.5.13-r0 | 9.5.13-r0 |
| postgresql | postgresql | >= 0 < 9.6.9-r0 | 9.6.9-r0 |
| postgresql | postgresql | >= 0 < 9.6.9-r0 | 9.6.9-r0 |
| postgresql | postgresql | >= 0 < 10.4-r0 | 10.4-r0 |
| postgresql | postgresql | >= 0 < 10.4-r0 | 10.4-r0 |
| postgresql | postgresql | >= 0 < 10.4-r0 | 10.4-r0 |
| postgresql | postgresql | >= 10.0 < 10.4 | 10.4 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv3.04.2MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
postgresql: Too-permissive access control list on function pg_logfile_rotate()
vendor_redhat·2018-05-10·CVSS 9.1
CVE-2018-1115 [CRITICAL] CWE-732 postgresql: Too-permissive access control list on function pg_logfile_rotate()
postgresql: Too-permissive access control list on function pg_logfile_rotate()
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.
It was found that pg_catalog.pg_logfile_rotate(), from the adminpack extension, did not follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could use this flaw to force log rotation.
Statement: This issue does not appear to affect the versions of postgresql as shipped with Red Hat Satellite version 5, CloudForms version 4, Red Hat Single Sign-On 7, and
GHSA
GHSA-54w7-jv4g-qhqg: postgresql before versions 10
ghsa_unreviewed·2022-05-13
CVE-2018-1115 [CRITICAL] CWE-732 GHSA-54w7-jv4g-qhqg: postgresql before versions 10
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.
OSV
CVE-2018-1115: postgresql before versions 10
osv·2018-05-10·CVSS 9.1
CVE-2018-1115 [CRITICAL] CVE-2018-1115: postgresql before versions 10
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1115 postgresql: Too-permissive access control list on function pg_logfile_rotate() [fedora-all]
bugzilla·2018-05-10·CVSS 9.1
CVE-2018-1115 [CRITICAL] CVE-2018-1115 postgresql: Too-permissive access control list on function pg_logfile_rotate() [fedora-all]
CVE-2018-1115 postgresql: Too-permissive access control list on function pg_logfile_rotate() [fedora-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1573276,1576773
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest th
Bugzilla
CVE-2018-1115 mingw-postgresql: postgresql: Too-permissive access control list on function pg_logfile_rotate() [fedora-all]
bugzilla·2018-05-10·CVSS 9.1
CVE-2018-1115 [CRITICAL] CVE-2018-1115 mingw-postgresql: postgresql: Too-permissive access control list on function pg_logfile_rotate() [fedora-all]
CVE-2018-1115 mingw-postgresql: postgresql: Too-permissive access control list on function pg_logfile_rotate() [fedora-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1573276,1576772
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=
Bugzilla
CVE-2018-1115 mingw-postgresql: postgresql: Too-permissive access control list on function pg_logfile_rotate() [epel-7]
bugzilla·2018-05-10·CVSS 9.1
CVE-2018-1115 [CRITICAL] CVE-2018-1115 mingw-postgresql: postgresql: Too-permissive access control list on function pg_logfile_rotate() [epel-7]
CVE-2018-1115 mingw-postgresql: postgresql: Too-permissive access control list on function pg_logfile_rotate() [epel-7]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1573276,1576771
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
Bugzilla
CVE-2018-1115 postgresql: Too-permissive access control list on function pg_logfile_rotate()
bugzilla·2018-04-30·CVSS 9.1
CVE-2018-1115 [CRITICAL] CVE-2018-1115 postgresql: Too-permissive access control list on function pg_logfile_rotate()
CVE-2018-1115 postgresql: Too-permissive access control list on function pg_logfile_rotate()
PostgreSQL contrib module "adminpack" installs function pg_logfile_rotate(), a
deprecated alias for built-in function pg_rotate_logfile(). By default, only
superusers can execute pg_rotate_logfile(), but anyone can execute
pg_logfile_rotate(). In certain configurations, an attacker could use this to
crash the server or distribute log messages across more log files than the
administrator wished.
Vulnerable Versions: 9.6, 10
Discussion:
Acknowledgments:
Name: the PostgreSQL project
Upstream: Stephen Frost
---
Statement:
This issue does not appear to affect the versions of postgresql as shipped with Red Hat Satellite version 5, CloudForms version 4, Red Hat Single Sign-On 7, and Fuse Service W
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.htmlhttp://www.securityfocus.com/bid/104285https://access.redhat.com/errata/RHSA-2018:2565https://access.redhat.com/errata/RHSA-2018:2566https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1115https://git.postgresql.org/gitweb/?p=postgresql.git%3Ba=commitdiff%3Bh=7b34740https://security.gentoo.org/glsa/201810-08http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00043.htmlhttp://www.securityfocus.com/bid/104285https://access.redhat.com/errata/RHSA-2018:2565https://access.redhat.com/errata/RHSA-2018:2566https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1115https://git.postgresql.org/gitweb/?p=postgresql.git%3Ba=commitdiff%3Bh=7b34740https://security.gentoo.org/glsa/201810-08
2018-05-10
Published