Bug 1573276 (CVE-2018-1115)
Summary: | CVE-2018-1115 postgresql: Too-permissive access control list on function pg_logfile_rotate() | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Pedro Sampaio <psampaio> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | abergmann, aileenc, bkearney, chazlett, cpelland, dajohnso, databases-maint, devrim, dffrench, drieden, drusso, gblomqui, gmccullo, gtanzill, gvarsami, hhorak, hhudgeon, jcoleman, jfrey, jhardy, jmadigan, jmlich83, jorton, jprause, jshepherd, jstanek, kconner, krathod, ldimaggi, lgriffin, loleary, meissner, mike, ngough, nwallace, obarenbo, pdrozd, pkubat, praiskup, pwright, roliveri, rrajasek, rwagner, security-response-team, simaishi, spinder, sthorger, tcunning, tgl, theute, tkirby, tlestach, trepel |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | postegresql 10.4, postegresql 9.6.9 | Doc Type: | If docs needed, set a value |
Doc Text: |
It was found that pg_catalog.pg_logfile_rotate(), from the adminpack extension, did not follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could use this flaw to force log rotation.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2019-06-10 10:20:51 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1576393, 1576394, 1576771, 1576772, 1576773, 1576774, 1614337, 1614340 | ||
Bug Blocks: | 1573278 |
Description
Pedro Sampaio
2018-04-30 17:39:21 UTC
Acknowledgments: Name: the PostgreSQL project Upstream: Stephen Frost Statement: This issue does not appear to affect the versions of postgresql as shipped with Red Hat Satellite version 5, CloudForms version 4, Red Hat Single Sign-On 7, and Fuse Service Works 6. Created mingw-postgresql tracking bugs for this issue: Affects: epel-7 [bug 1576771] Affects: fedora-all [bug 1576772] Created postgresql tracking bugs for this issue: Affects: fedora-all [bug 1576773] This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS Via RHSA-2018:2565 https://access.redhat.com/errata/RHSA-2018:2565 This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 6 Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS Via RHSA-2018:2566 https://access.redhat.com/errata/RHSA-2018:2566 This vulnerability is out of security support scope for the following product: * Red Hat JBoss Operations Network 3 Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details. |