Arbitrary code execution in Oracle Linux and PostgreSQL - CVE-2016-5423

 

Arbitrary code execution in Oracle Linux and PostgreSQL - CVE-2016-5423

Published: August 15, 2016 / Updated: January 11, 2017


Vulnerability identifier: #VU314
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5423
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code,

The vulnerability exists in PostgreSQL. A remote authenticated attacker can cause the target server to crash, disclose portions of server memory, or potentially execute arbitrary code by submiting specially crafted SQL statements containing CASE/WHEN commands.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Oracle Linux
Debian Linux
Arch Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Ubuntu
Fedora
PostgreSQL
Red Hat Satellite
postgresql (Alpine package)
postgresql92-postgresql (Red Hat package)
rh-postgresql94-postgresql (Red Hat package)
postgresql
rh-postgresql95-postgresql (Red Hat package)

How to mitigate CVE-2016-5423

Install the following versions: (9.1.23, 9.2.18, 9.3.14, 9.4.9, 9.5.4).

postgresql (Alpine package) - update to 9.3.14-r0
postgresql92-postgresql (Red Hat package) - addressed in versions 9.2.18-1.el6, 9.2.18-1.el7
rh-postgresql94-postgresql (Red Hat package) - addressed in versions 9.4.9-1.el6, 9.4.9-1.el7
postgresql - addressed in versions 9.4.9-1.fc23, 9.5.4-1.fc24, 9.5.4-1.fc25
rh-postgresql95-postgresql (Red Hat package) - addressed in versions 9.5.4-1.el6, 9.5.4-1.el7

External References

Related Security Bulletins