Disclosure of user information in Oracle Linux and PostgreSQL - CVE-2016-5424

 

Disclosure of user information in Oracle Linux and PostgreSQL - CVE-2016-5424

Published: August 15, 2016 / Updated: November 22, 2018


Vulnerability identifier: #VU315
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5424
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain elevated privileges on the target system.

The vulnerability exists in PostgreSQL. A remote authenticated attacker with CREATEDB or CREATEROLE roles can gain elevated privileges on the target system by creating a specially crafted object name containing newlines, carriage returns, double quotes, or backslashes.

Successful exploitation of this vulnerability may result in disclosure of user information.


Affected software

Oracle Linux
Debian Linux
Arch Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Ubuntu
Fedora
PostgreSQL
Red Hat Satellite
postgresql (Alpine package)
postgresql92-postgresql (Red Hat package)
rh-postgresql94-postgresql (Red Hat package)
postgresql
rh-postgresql95-postgresql (Red Hat package)

How to mitigate CVE-2016-5424

Install the following versions: (9.1.23, 9.2.18, 9.3.14, 9.4.9, 9.5.4).

postgresql (Alpine package) - update to 9.3.14-r0
postgresql92-postgresql (Red Hat package) - addressed in versions 9.2.18-1.el6, 9.2.18-1.el7
rh-postgresql94-postgresql (Red Hat package) - addressed in versions 9.4.9-1.el6, 9.4.9-1.el7
postgresql - addressed in versions 9.4.9-1.fc23, 9.5.4-1.fc24, 9.5.4-1.fc25
rh-postgresql95-postgresql (Red Hat package) - addressed in versions 9.5.4-1.el6, 9.5.4-1.el7

External References

Related Security Bulletins