Permissions, Privileges, and Access Controls in postgresql (Alpine package)



Published: 2016-02-16
Risk High
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2016-0766
CWE-ID CWE-264
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
postgresql (Alpine package)
Operating systems & Components / Operating system package or component

Vendor Alpine Linux Development Team

Security Bulletin

This security bulletin contains one high risk vulnerability.

1) Permissions, Privileges, and Access Controls

EUVDB-ID: #VU32338

Risk: High

CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2016-0766

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to execute arbitrary code.

PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privileges via unspecified vectors.

Mitigation

Install update from vendor's website.

Vulnerable software versions

postgresql (Alpine package): 9.1.3-r0 - 9.3.10-r0

External links

http://git.alpinelinux.org/aports/commit/?id=de54eeef246ed1ee8fcba3da5c559af490d2e2e9
http://git.alpinelinux.org/aports/commit/?id=87879a3f27f9101b4c265ef56b479dbe23fd41c9
http://git.alpinelinux.org/aports/commit/?id=702b09615bb3319131fb1a8aeb19ff42bc312a29
http://git.alpinelinux.org/aports/commit/?id=65b5dd4abceafa43b63560e421f11671eeef5940


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###