First published: Thu Nov 09 2017(Updated: )
Dawid Golunski discovered that the postgresql-common pg_ctlcluster script incorrectly handled symlinks. A local attacker could possibly use this issue to escalate privileges. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-1255) It was discovered that the postgresql-common helper scripts incorrectly handled symlinks. A local attacker could possibly use this issue to escalate privileges. (CVE-2017-8806)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/postgresql-common | <184ubuntu1.1 | 184ubuntu1.1 |
Ubuntu Ubuntu | =17.10 | |
All of | ||
ubuntu/postgresql-common | <179ubuntu0.1 | 179ubuntu0.1 |
Ubuntu Ubuntu | =17.04 | |
All of | ||
ubuntu/postgresql-common | <173ubuntu0.1 | 173ubuntu0.1 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/postgresql-common | <154ubuntu1.1 | 154ubuntu1.1 |
Ubuntu Ubuntu | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.