First published: Thu Mar 01 2018(Updated: )
A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
PostgreSQL | <9.4-0.5.3.1 | |
SUSE Linux Enterprise Server | =11-sp3 |
Update to the update packages.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14798 is a vulnerability in the postgresql init script that can be exploited to escalate privileges to root.
CVE-2017-14798 has a severity level of high (7).
CVE-2017-14798 affects the following software: Postgresql version up to 9.4-0.5.3.1 and Suse Linux Enterprise Server version 11-sp3.
An attacker with access to the postgresql account can exploit CVE-2017-14798 by exploiting the race condition in the postgresql init script to escalate their privileges to root.
Yes, a fix is available for CVE-2017-14798. Please refer to the provided references for more information on how to apply the fix.