Risk | High |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2016-0766 |
CWE-ID | CWE-264 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
postgresql (Alpine package) Operating systems & Components / Operating system package or component |
Vendor | Alpine Linux Development Team |
Security Bulletin
This security bulletin contains one high risk vulnerability.
EUVDB-ID: #VU32338
Risk: High
CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2016-0766
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a remote authenticated user to execute arbitrary code.
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privileges via unspecified vectors.
MitigationInstall update from vendor's website.
Vulnerable software versionspostgresql (Alpine package): 9.1.3-r0 - 9.3.10-r0
External linkshttp://git.alpinelinux.org/aports/commit/?id=de54eeef246ed1ee8fcba3da5c559af490d2e2e9
http://git.alpinelinux.org/aports/commit/?id=87879a3f27f9101b4c265ef56b479dbe23fd41c9
http://git.alpinelinux.org/aports/commit/?id=702b09615bb3319131fb1a8aeb19ff42bc312a29
http://git.alpinelinux.org/aports/commit/?id=65b5dd4abceafa43b63560e421f11671eeef5940
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.