Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.882819
Kategorie:CentOS Local Security Checks
Titel:CentOS Update for postgresql CESA-2017:3402 centos7
Zusammenfassung:Check the version of postgresql
Beschreibung:Summary:
Check the version of postgresql

Vulnerability Insight:
PostgreSQL is an advanced object-relational
database management system (DBMS).

Security Fix(es):

* Privilege escalation flaws were found in the initialization scripts of
PostgreSQL. An attacker with access to the postgres user account could use
these flaws to obtain root access on the server machine. (CVE-2017-12172,
CVE-2017-15097)

Note: This patch drops the script privileges from root to the postgres
user. Therefore, this update works properly only if the postgres user has
write access to the postgres' home directory, such as the one in the
default configuration (/var/lib/pgsql).

Red Hat would like to thank the PostgreSQL project for reporting
CVE-2017-12172. The CVE-2017-15097 issue was discovered by Pedro Barbosa
(Red Hat) and the PostgreSQL project. Upstream acknowledges Antoine Scemama
(Brainloop) as the original reporter of these issues.

Affected Software/OS:
postgresql on CentOS 7

Solution:
Please Install the Updated Packages.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-12172
BugTraq ID: 101949
http://www.securityfocus.com/bid/101949
https://www.postgresql.org/support/security/
RedHat Security Advisories: RHSA-2017:3402
https://access.redhat.com/errata/RHSA-2017:3402
RedHat Security Advisories: RHSA-2017:3403
https://access.redhat.com/errata/RHSA-2017:3403
RedHat Security Advisories: RHSA-2017:3404
https://access.redhat.com/errata/RHSA-2017:3404
RedHat Security Advisories: RHSA-2017:3405
https://access.redhat.com/errata/RHSA-2017:3405
http://www.securitytracker.com/id/1039752
Common Vulnerability Exposure (CVE) ID: CVE-2017-15097
1039983
http://www.securitytracker.com/id/1039983
RHSA-2017:3402
RHSA-2017:3403
RHSA-2017:3404
RHSA-2017:3405
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15097
CopyrightCopyright (C) 2017 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.