Rapid7

vulnerability

Alpine Linux: CVE-2016-5424: postgresql Security Issues

Severity
5
CVSS
(AV:N/AC:H/Au:S/C:P/I:P/A:P)
Published
Dec 9, 2016
Added
Aug 30, 2017
Modified
Jan 8, 2018

Description

PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a (1) " (double quote), (2) \ (backslash), (3) carriage return, or (4) newline character in a (a) database or (b) role name that is mishandled during an administrative operation.

Solution

alpine-linux-upgrade-postgresql

References

    Title
    Rapid7 Labs

    2026 Global Threat Landscape Report

    The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.