Red Hat Bugzilla – Bug 1573276
CVE-2018-1115 postgresql: Too-permissive access control list on function pg_logfile_rotate()
Last modified: 2018-08-27 04:35:26 EDT
PostgreSQL contrib module "adminpack" installs function pg_logfile_rotate(), a deprecated alias for built-in function pg_rotate_logfile(). By default, only superusers can execute pg_rotate_logfile(), but anyone can execute pg_logfile_rotate(). In certain configurations, an attacker could use this to crash the server or distribute log messages across more log files than the administrator wished. Vulnerable Versions: 9.6, 10
Acknowledgments: Name: the PostgreSQL project Upstream: Stephen Frost
Statement: This issue does not appear to affect the versions of postgresql as shipped with Red Hat Satellite version 5, CloudForms version 4, Red Hat Single Sign-On 7, and Fuse Service Works 6.
Created mingw-postgresql tracking bugs for this issue: Affects: epel-7 [bug 1576771] Affects: fedora-all [bug 1576772] Created postgresql tracking bugs for this issue: Affects: fedora-all [bug 1576773]
Upstream fix: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=7b34740
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS Via RHSA-2018:2565 https://access.redhat.com/errata/RHSA-2018:2565
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 6 Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS Via RHSA-2018:2566 https://access.redhat.com/errata/RHSA-2018:2566