Security restrictions bypass in PostgreSQL - CVE-2018-1115
Published: May 15, 2018 / Updated: May 15, 2018
Vulnerability identifier: #VU12652
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H]
CVE-ID: CVE-2018-1115
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to bypass security restrictions on the target system.
The weakness exists in the pg_catalog.pg_logfile_rotate() function due to improper Access Control List (ACL) restrictions as it does not follow the same ACLs as the pg_rorate_logfile function. A remote attacker can connect to the database and cause the target software to force log rotation, write log messages across arbitrary log files or cause the service to crash.
The weakness exists in the pg_catalog.pg_logfile_rotate() function due to improper Access Control List (ACL) restrictions as it does not follow the same ACLs as the pg_rorate_logfile function. A remote attacker can connect to the database and cause the target software to force log rotation, write log messages across arbitrary log files or cause the service to crash.
Affected software
PostgreSQL
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
postgresql (Alpine package)
openSUSE Leap
postgresql
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
postgresql (Alpine package)
openSUSE Leap
postgresql
How to mitigate CVE-2018-1115
Update to version 10.4 or 9.6.9.
postgresql (Alpine package) - update to 9.5.13-r0
postgresql - addressed in versions 9.6.9-1.fc26, 9.6.9-1.fc27, 10.4-1.fc28
postgresql - addressed in versions 9.6.9-1.fc26, 9.6.9-1.fc27, 10.4-1.fc28
External References
Related Security Bulletins
- Security restrictions bypass in PostgreSQL
- OpenSUSE Linux update for postgresql96
- openSUSE update for postgresql95
- Red Hat update for PostgreSQL
- Red Hat update for PostgreSQL
- OpenSUSE Linux update for postgresql10
- Gentoo update for PostgreSQL
- Amazon Linux AMI update for postgresql96
- OpenSUSE Linux update for postgresql96, postgresql10 and postgresql12
- Security restrictions bypass in postgresql (Alpine package)
- Fedora 26 update for postgresql
- Fedora 27 update for postgresql
- Fedora 28 update for postgresql