Back

CRITICAL

postgresql: Too-permissive access control list on function pg_logfile_rotate()

Published May 10, 2018

Description

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.

Affected products

Remediation

Red Hat statement

This issue does not appear to affect the versions of postgresql as shipped with Red Hat Satellite version 5, CloudForms version 4, Red Hat Single Sign-On 7, and Fuse Service Works 6.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 10, 2018
Updated Aug 5, 2024
Reserved Dec 4, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date May 10, 2018
ENISA EUVD
Assigner redhat
Published May 10, 2018
Updated Aug 5, 2024
Exploited since n/a
EUVD-2018-11759