The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade postgresql-common | Mar 26, 2024 | Nov 20, 2019 |
| Debian | — | Upgrade postgresql-common | Nov 18, 2019 | Nov 18, 2019 |
| Postgres | — | Upgrade to PostgreSQL version 12.1 | Dec 5, 2019 | Nov 20, 2019 |
| Ubuntu | — | Upgrade postgresql-common (Ubuntu Pro)Upgrade postgresql-common | Nov 15, 2019 | Nov 14, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub