USN-3476-1: postgresql-common vulnerabilities
Dawid Golunski discovered that the postgresql-common pgctlcluster script incorrectly handled symlinks. A local attacker could possibly use this issue to escalate privileges. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-1255) It was discovered that the postgresql-common helper scripts incorrectly handled symlinks. A local attacker could possibly use this issue to escalate privileges. (CVE-2017-8806)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-3476-1?
USN-3476-1 has been classified as a privilege escalation vulnerability affecting specific versions of postgresql-common.
How do I fix USN-3476-1?
To fix USN-3476-1, upgrade the postgresql-common package to the appropriate remedied version for your Ubuntu distribution.
Which Ubuntu versions are affected by USN-3476-1?
USN-3476-1 affects Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
What kind of attack does USN-3476-1 allow?
USN-3476-1 could allow a local attacker to escalate privileges on the affected systems.
Who discovered the vulnerability in USN-3476-1?
The vulnerability in USN-3476-1 was discovered by Dawid Golunski.