CVE-2017-8806

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2017-8806
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-8806.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-8806
Aliases
Related
Published
2017-11-13T09:29:00Z
Modified
2024-10-22T05:29:13.936985Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

The Debian pgctlcluster, pgcreatecluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files.

References

Affected packages

Debian:11 / postgresql-common

Package

Name
postgresql-common
Purl
pkg:deb/debian/postgresql-common?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
188

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / postgresql-common

Package

Name
postgresql-common
Purl
pkg:deb/debian/postgresql-common?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
188

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / postgresql-common

Package

Name
postgresql-common
Purl
pkg:deb/debian/postgresql-common?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
188

Ecosystem specific

{
    "urgency": "not yet assigned"
}