Disclosure of user information in Oracle Linux and PostgreSQL - CVE-2016-5424
Published: August 15, 2016 / Updated: November 22, 2018
Vulnerability identifier: #VU315
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5424
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain elevated privileges on the target system.
The vulnerability exists in PostgreSQL. A remote authenticated attacker with CREATEDB or CREATEROLE roles can gain elevated privileges on the target system by creating a specially crafted object name containing newlines, carriage returns, double quotes, or backslashes.
Successful exploitation of this vulnerability may result in disclosure of user information.
The vulnerability exists in PostgreSQL. A remote authenticated attacker with CREATEDB or CREATEROLE roles can gain elevated privileges on the target system by creating a specially crafted object name containing newlines, carriage returns, double quotes, or backslashes.
Successful exploitation of this vulnerability may result in disclosure of user information.
Affected software
Oracle Linux
Debian Linux
Arch Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Ubuntu
Fedora
PostgreSQL
Red Hat Satellite
postgresql (Alpine package)
postgresql92-postgresql (Red Hat package)
rh-postgresql94-postgresql (Red Hat package)
postgresql
rh-postgresql95-postgresql (Red Hat package)
Debian Linux
Arch Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Ubuntu
Fedora
PostgreSQL
Red Hat Satellite
postgresql (Alpine package)
postgresql92-postgresql (Red Hat package)
rh-postgresql94-postgresql (Red Hat package)
postgresql
rh-postgresql95-postgresql (Red Hat package)
How to mitigate CVE-2016-5424
Install the following versions: (9.1.23, 9.2.18, 9.3.14, 9.4.9, 9.5.4).
postgresql (Alpine package) - update to 9.3.14-r0
postgresql92-postgresql (Red Hat package) - addressed in versions 9.2.18-1.el6, 9.2.18-1.el7
rh-postgresql94-postgresql (Red Hat package) - addressed in versions 9.4.9-1.el6, 9.4.9-1.el7
postgresql - addressed in versions 9.4.9-1.fc23, 9.5.4-1.fc24, 9.5.4-1.fc25
rh-postgresql95-postgresql (Red Hat package) - addressed in versions 9.5.4-1.el6, 9.5.4-1.el7
postgresql92-postgresql (Red Hat package) - addressed in versions 9.2.18-1.el6, 9.2.18-1.el7
rh-postgresql94-postgresql (Red Hat package) - addressed in versions 9.4.9-1.el6, 9.4.9-1.el7
postgresql - addressed in versions 9.4.9-1.fc23, 9.5.4-1.fc24, 9.5.4-1.fc25
rh-postgresql95-postgresql (Red Hat package) - addressed in versions 9.5.4-1.el6, 9.5.4-1.el7
External References
Related Security Bulletins
- Debian update for postgresql-9.4
- Ubuntu update for PostgreSQL
- Arch Linux update for postgresql
- OpenSUSE Linux update for postgresql93
- SUSE Linux update for postgresql94
- SUSE Linux update for postgresql94
- SUSE Linux update for postgresql93
- OpenSUSE Linux update for postgresql94
- OpenSUSE Linux update for postgresql93
- Amazon Linux AMI update for postgresql92, postgresql93, postgresql94
- Red Hat update for rh-postgresql95-postgresql
- Disclosure of user information in postgresql (Alpine package)
- Gentoo update for PostgreSQL
- Fedora 23 update for postgresql
- Fedora 25 update for postgresql
- Fedora 24 update for postgresql
- Red Hat Software Collections update for rh-postgresql94-postgresql
- Red Hat Software Collections update for rh-postgresql95-postgresql
- Red Hat Software Collections update for postgresql92-postgresql