Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | centos-upgrade-postgresqlcentos-upgrade-postgresql-contribcentos-upgrade-postgresql-debuginfocentos-upgrade-postgresql-develcentos-upgrade-postgresql-docscentos-upgrade-postgresql-libscentos-upgrade-postgresql-plperlcentos-upgrade-postgresql-plpythoncentos-upgrade-postgresql-pltclcentos-upgrade-postgresql-servercentos-upgrade-postgresql-staticcentos-upgrade-postgresql-testcentos-upgrade-postgresql-upgrade | Dec 12, 2017 | Dec 8, 2017 |
| Huawei Euleros 2_0_sp1 | huawei-euleros-2_0_sp1-upgrade-postgresqlhuawei-euleros-2_0_sp1-upgrade-postgresql-contribhuawei-euleros-2_0_sp1-upgrade-postgresql-develhuawei-euleros-2_0_sp1-upgrade-postgresql-docshuawei-euleros-2_0_sp1-upgrade-postgresql-libshuawei-euleros-2_0_sp1-upgrade-postgresql-plperlhuawei-euleros-2_0_sp1-upgrade-postgresql-plpythonhuawei-euleros-2_0_sp1-upgrade-postgresql-pltclhuawei-euleros-2_0_sp1-upgrade-postgresql-serverhuawei-euleros-2_0_sp1-upgrade-postgresql-test | Oct 11, 2019 | Jul 27, 2018 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-postgresqlhuawei-euleros-2_0_sp2-upgrade-postgresql-contribhuawei-euleros-2_0_sp2-upgrade-postgresql-develhuawei-euleros-2_0_sp2-upgrade-postgresql-docshuawei-euleros-2_0_sp2-upgrade-postgresql-libshuawei-euleros-2_0_sp2-upgrade-postgresql-plperlhuawei-euleros-2_0_sp2-upgrade-postgresql-plpythonhuawei-euleros-2_0_sp2-upgrade-postgresql-pltclhuawei-euleros-2_0_sp2-upgrade-postgresql-serverhuawei-euleros-2_0_sp2-upgrade-postgresql-test | Oct 11, 2019 | Jul 27, 2018 | |
| Oracle_linux | — | oracle-linux-upgrade-postgresqloracle-linux-upgrade-postgresql-contriboracle-linux-upgrade-postgresql-develoracle-linux-upgrade-postgresql-docsoracle-linux-upgrade-postgresql-libsoracle-linux-upgrade-postgresql-plperloracle-linux-upgrade-postgresql-plpythonoracle-linux-upgrade-postgresql-pltcloracle-linux-upgrade-postgresql-serveroracle-linux-upgrade-postgresql-staticoracle-linux-upgrade-postgresql-testoracle-linux-upgrade-postgresql-upgrade | Dec 8, 2017 | Dec 7, 2017 |
| Redhat_linux | — | redhat-upgrade-postgresqlredhat-upgrade-postgresql-contribredhat-upgrade-postgresql-debuginforedhat-upgrade-postgresql-develredhat-upgrade-postgresql-docsredhat-upgrade-postgresql-libsredhat-upgrade-postgresql-plperlredhat-upgrade-postgresql-plpythonredhat-upgrade-postgresql-pltclredhat-upgrade-postgresql-serverredhat-upgrade-postgresql-staticredhat-upgrade-postgresql-testredhat-upgrade-postgresql-upgrade | Dec 8, 2017 | Dec 8, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub