CVE-2017-15097: High severity red hat enterprise linux desktop vulnerability
PostgreSQL runs under a non-root operating system account, and database superusers have effective ability to run arbitrary code under that system account. Red Hat provides scripts for starting the database server during system boot and for initializing the database. These implementations use file names that the database superuser can replace with symbolic links. As root, the scripts open(), chmod() and/or chown() the log and data files. These issues often suffice for the database superuser to escalate to root privileges when root starts the server or initializes the database.
Other sources
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15097?
CVE-2017-15097 has a high severity rating due to the potential for privilege escalation.
How do I fix CVE-2017-15097?
To fix CVE-2017-15097, apply the latest security patches provided by Red Hat for the affected versions.
What systems are affected by CVE-2017-15097?
CVE-2017-15097 affects Red Hat Enterprise Linux Desktop 7.0, Red Hat Enterprise Linux Server 7.0, and other specified versions.
What type of vulnerability is CVE-2017-15097?
CVE-2017-15097 is a privilege escalation vulnerability that allows an attacker to gain root access.
Who can exploit CVE-2017-15097?
An attacker with access to the postgres user account can exploit CVE-2017-15097 to escalate privileges.