postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesnt follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Postgresql | Postgresql | * | 9.6.9 (excluding) |
Postgresql | Postgresql | 10.0 (including) | 10.4 (excluding) |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | rh-postgresql96-postgresql-0:9.6.10-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | RedHat | rh-postgresql96-postgresql-0:9.6.10-1.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-postgresql10-postgresql-0:10.5-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-postgresql96-postgresql-0:9.6.10-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | RedHat | rh-postgresql10-postgresql-0:10.5-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | RedHat | rh-postgresql96-postgresql-0:9.6.10-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | RedHat | rh-postgresql10-postgresql-0:10.5-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | RedHat | rh-postgresql96-postgresql-0:9.6.10-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | RedHat | rh-postgresql10-postgresql-0:10.5-1.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | RedHat | rh-postgresql96-postgresql-0:9.6.10-1.el7 | * |
Postgresql-10 | Ubuntu | bionic | * |
Postgresql-10 | Ubuntu | upstream | * |
Postgresql-9.6 | Ubuntu | artful | * |
Postgresql-9.6 | Ubuntu | upstream | * |