First published: Wed Sep 21 2016(Updated: )
The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download software.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PostgreSQL JDBC Driver | <9.1.24 | |
PostgreSQL JDBC Driver | >=9.2<9.2.19 | |
PostgreSQL JDBC Driver | >=9.3<9.3.15 | |
PostgreSQL JDBC Driver | >=9.4.0<9.4.10 | |
PostgreSQL JDBC Driver | >=9.5.0<9.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7048 has a medium severity rating due to its potential to allow remote code execution.
To fix CVE-2016-7048, upgrade to PostgreSQL version 9.3.15, 9.4.10, or 9.5.5 or later.
CVE-2016-7048 affects PostgreSQL versions before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5.
CVE-2016-7048 can facilitate remote code execution attacks through the insecure use of HTTP in the interactive installer.
The best recommendation for CVE-2016-7048 is to upgrade to a secure version as there are no effective workarounds.