Description
The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, in Ubuntu 14.04 LTS before 154ubuntu1.1, in Ubuntu 16.04 LTS before 173ubuntu0.1, in Ubuntu 17.04 before 179ubuntu0.1, and in Ubuntu 17.10 before 184ubuntu1.1 allows local users to gain root privileges via a symlink attack on a logfile in /var/log/postgresql.
Published: 2017-12-05
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-774-1 postgresql-common security update
EUVD EUVD EUVD-2016-2354 The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, in Ubuntu 14.04 LTS before 154ubuntu1.1, in Ubuntu 16.04 LTS before 173ubuntu0.1, in Ubuntu 17.04 before 179ubuntu0.1, and in Ubuntu 17.10 before 184ubuntu1.1 allows local users to gain root privileges via a symlink attack on a logfile in /var/log/postgresql.
Ubuntu USN Ubuntu USN USN-3476-1 postgresql-common vulnerabilities
Ubuntu USN Ubuntu USN USN-3476-2 postgresql-common vulnerabilities
History

No history.

Subscriptions

Canonical Ubuntu Linux
Debian Debian Linux Postgresql-common
cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published:

Updated: 2024-08-05T22:48:13.668Z

Reserved: 2015-12-27T00:00:00.000Z

Link: CVE-2016-1255

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-12-05T16:29:00.373

Modified: 2025-04-20T01:37:25.860

Link: CVE-2016-1255

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses