SB2017120609 - Amazon Linux AMI update for postgresql95, postgresql96
Published: December 6, 2017
Security Bulletin ID
SB2017120609
Severity
Low
Patch available
YES
Number of vulnerabilities
3
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Improper access control (CVE-ID: CVE-2017-12172)
The vulnerability allows a local attacker to cause DoS condition or obtain potentially sensitive information on a targeted system.The weakness exists due to a flaw in certain non-default startup scripts. A local attacker with the privileges of the database server can create a symbolic link from the $PGLOG file to a critical file and modify the target file.
2) Security restrictions bypass (CVE-ID: CVE-2017-15099)
The vulnerability allows a remote attacker to bypass security restrictions on a targeted system.The weakness exists due to improper security restrictions in the case of an arbiter specified by constraint name. A remote attacker can submit specially crafted INSERT requests and bypass security controls on the update path of 'INSERT ... ON CONFLICT DO UPDATE' function to conduct further attacks.
3) Data handling (CVE-ID: CVE-2017-15098)
The vulnerability allows a remote authenticated attacker to cause DoS condition or obtain potentially sensitive information on a targeted system.The weakness exists due to improper data handling. A remote attacker can send specially crafted data to trigger a rowtype mismatch in json{b}_populate_recordset(), cause the application to crash or read arbitrary data.
Remediation
Install update from vendor's website.