Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2018.0137
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2018-0137)
Summary:The remote host is missing an update for the 'postgresql9.4, postgresql9.6' package(s) announced via the MGASA-2018-0137 advisory.
Description:Summary:
The remote host is missing an update for the 'postgresql9.4, postgresql9.6' package(s) announced via the MGASA-2018-0137 advisory.

Vulnerability Insight:
In postgresql 9.4.x before 9.4.16 and 9.6.x before 9.6.7, pg_upgrade creates
file in current working directory containing the output of `pg_dumpall -g`
under umask which was in effect when the user invoked pg_upgrade, and not
under 0077 which is normally used for other temporary files. This can allow
an authenticated attacker to read or modify the one file, which may contain
encrypted or unencrypted database passwords. The attack is infeasible if a
directory mode blocks the attacker searching the current working directory or
if the prevailing umask blocks the attacker opening the file (CVE-2018-1053).

Note that on Mageia 5, only the postgresql9.4 update is being provided. Users
of the postgresql9.3 package should migrate to 9.4.

Affected Software/OS:
'postgresql9.4, postgresql9.6' package(s) on Mageia 5, Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
3.3

CVSS Vector:
AV:L/AC:M/Au:N/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-1053
BugTraq ID: 102986
http://www.securityfocus.com/bid/102986
https://lists.debian.org/debian-lts-announce/2018/02/msg00006.html
RedHat Security Advisories: RHSA-2018:2511
https://access.redhat.com/errata/RHSA-2018:2511
RedHat Security Advisories: RHSA-2018:2566
https://access.redhat.com/errata/RHSA-2018:2566
RedHat Security Advisories: RHSA-2018:3816
https://access.redhat.com/errata/RHSA-2018:3816
https://usn.ubuntu.com/3564-1/
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.