A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade postgresql-contribUpgrade postgresql-server-develUpgrade postgresql-plpythonUpgrade postgresql-pltclUpgrade postgresql-plperlUpgrade postgresql-serverUpgrade postgresqlUpgrade postgresql-initUpgrade postgresql-docsUpgrade postgresql-testUpgrade postgresql-devel | Nov 27, 2017 | Nov 27, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub