CVE-2017-14798: local privilege escalation in SUSE postgresql init script
A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2017-14798?
CVE-2017-14798 is a vulnerability in the postgresql init script that can be exploited to escalate privileges to root.
What is the severity of CVE-2017-14798?
CVE-2017-14798 has a severity level of high (7).
Which software is affected by CVE-2017-14798?
CVE-2017-14798 affects the following software: Postgresql version up to 9.4-0.5.3.1 and Suse Linux Enterprise Server version 11-sp3.
How can an attacker exploit CVE-2017-14798?
An attacker with access to the postgresql account can exploit CVE-2017-14798 by exploiting the race condition in the postgresql init script to escalate their privileges to root.
Is there a fix for CVE-2017-14798?
Yes, a fix is available for CVE-2017-14798. Please refer to the provided references for more information on how to apply the fix.