PostgreSQL contrib module "adminpack" installs function pg_logfile_rotate(), a deprecated alias for built-in function pg_rotate_logfile(). By default, only superusers can execute pg_rotate_logfile(), but anyone can execute pg_logfile_rotate(). In certain configurations, an attacker could use this to crash the server or distribute log messages across more log files than the administrator wished. Vulnerable Versions: 9.6, 10
Acknowledgments: Name: the PostgreSQL project Upstream: Stephen Frost
Statement: This issue does not appear to affect the versions of postgresql as shipped with Red Hat Satellite version 5, CloudForms version 4, Red Hat Single Sign-On 7, and Fuse Service Works 6.
Created mingw-postgresql tracking bugs for this issue: Affects: epel-7 [bug 1576771] Affects: fedora-all [bug 1576772] Created postgresql tracking bugs for this issue: Affects: fedora-all [bug 1576773]
Upstream fix: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=7b34740
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS Via RHSA-2018:2565 https://access.redhat.com/errata/RHSA-2018:2565
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 6 Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS Via RHSA-2018:2566 https://access.redhat.com/errata/RHSA-2018:2566
This vulnerability is out of security support scope for the following product: * Red Hat JBoss Operations Network 3 Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.