Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
postgresql-common could be made to overwrite files as the
administrator.
Software Description:
- postgresql-common: PostgreSQL database-cluster manager
Details:
USN-3476-1 fixed two vulnerabilities in postgresql-common. This update
provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Dawid Golunski discovered that the postgresql-common pg_ctlcluster
script incorrectly handled symlinks. A local attacker could possibly
use this issue to escalate privileges. (CVE-2016-1255)
It was discovered that the postgresql-common helper scripts
incorrectly handled symlinks. A local attacker could possibly use this
issue to escalate privileges. (CVE-2017-8806)
The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: postgresql-common 129ubuntu1.2 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-3476-2
https://ubuntu.com/security/notices/USN-3476-1
CVE-2016-1255, CVE-2017-8806
Get the latest Linux and open source security news straight to your inbox.