UBUNTU-CVE-2017-8806

See a problem?
Source
https://ubuntu.com/security/CVE-2017-8806
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-8806.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2017-8806
Related
Published
2017-11-09T00:00:00Z
Modified
2017-11-09T00:00:00Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
  • 5.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

The Debian pgctlcluster, pgcreatecluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files.

References

Affected packages

Ubuntu:14.04:LTS / postgresql-common

Package

Name
postgresql-common
Purl
pkg:deb/ubuntu/postgresql-common?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
154ubuntu1.1

Affected versions

Other

148
150
151
152
153
153bzr1
154
154ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "9.3+154ubuntu1.1",
            "binary_name": "postgresql"
        },
        {
            "binary_version": "9.3+154ubuntu1.1",
            "binary_name": "postgresql-client"
        },
        {
            "binary_version": "154ubuntu1.1",
            "binary_name": "postgresql-client-common"
        },
        {
            "binary_version": "154ubuntu1.1",
            "binary_name": "postgresql-common"
        },
        {
            "binary_version": "9.3+154ubuntu1.1",
            "binary_name": "postgresql-contrib"
        },
        {
            "binary_version": "9.3+154ubuntu1.1",
            "binary_name": "postgresql-doc"
        },
        {
            "binary_version": "154ubuntu1.1",
            "binary_name": "postgresql-server-dev-all"
        }
    ]
}

Ubuntu:16.04:LTS / postgresql-common

Package

Name
postgresql-common
Purl
pkg:deb/ubuntu/postgresql-common?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
173ubuntu0.1

Affected versions

Other

169git1
170
171
172
172ubuntu1
173

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "9.5+173ubuntu0.1",
            "binary_name": "postgresql"
        },
        {
            "binary_version": "9.5+173ubuntu0.1",
            "binary_name": "postgresql-client"
        },
        {
            "binary_version": "173ubuntu0.1",
            "binary_name": "postgresql-client-common"
        },
        {
            "binary_version": "173ubuntu0.1",
            "binary_name": "postgresql-common"
        },
        {
            "binary_version": "9.5+173ubuntu0.1",
            "binary_name": "postgresql-contrib"
        },
        {
            "binary_version": "9.5+173ubuntu0.1",
            "binary_name": "postgresql-doc"
        },
        {
            "binary_version": "173ubuntu0.1",
            "binary_name": "postgresql-server-dev-all"
        }
    ]
}