CVE Database
/

CVE-2018-1115

Back to search

CVE-2018-1115

Published: May 10, 2018

Modified: Aug 5, 2024

PUBLISHED

CVSS v3.0

4.2

MEDIUM

Description

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.

VendorProductVersions

unspecified

postgresql

affected
postegresql 10.4
affected
postegresql 9.6.9

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L

Attack Vector

Network

Attack Complexity

High

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

Low

Availability

Low

References

GLSA-201810-08
vendor-advisory
x_refsource_GENTOO
RHSA-2018:2566
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2565
vendor-advisory
x_refsource_REDHAT
104285
vdb-entry
x_refsource_BID
openSUSE-SU-2020:1227
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now