CVE-2016-0766

Published on: 02/17/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:13 PM UTC

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Certain versions of Ubuntu Linux from Canonical contain the following vulnerability:

PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privileges via unspecified vectors.

  • CVE-2016-0766 has been assigned by [email protected] to track the vulnerability - currently rated as HIGH severity.

CVSS3 Score: 8.8 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW LOW NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH HIGH HIGH

CVSS2 Score: 9 - HIGH

Access
Vector
Access
Complexity
Authentication
NETWORK LOW SINGLE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
COMPLETE COMPLETE COMPLETE

CVE References

Description Tags Link
Debian -- Security Information -- DSA-3475-1 postgresql-9.1 www.debian.org
Depreciated Link
text/html
URL Logo DEBIAN DSA-3475
PostgreSQL: Documentation: 9.5: Release 9.5.1 www.postgresql.org
text/html
URL Logo CONFIRM www.postgresql.org/docs/current/static/release-9-5-1.html
[security-announce] SUSE-SU-2016:0539-1: important: Security update for lists.opensuse.org
text/html
URL Logo SUSE SUSE-SU-2016:0539
[security-announce] SUSE-SU-2016:0555-1: important: Security update for lists.opensuse.org
text/html
URL Logo SUSE SUSE-SU-2016:0555
PostgreSQL: Multiple vulnerabilities (GLSA 201701-33) — Gentoo security security.gentoo.org
text/html
URL Logo GENTOO GLSA-201701-33
PostgreSQL: 2016-02-11 Security Update Release www.postgresql.org
text/html
URL Logo CONFIRM www.postgresql.org/about/news/1644/
USN-2894-1: PostgreSQL vulnerabilities | Ubuntu www.ubuntu.com
text/html
URL Logo UBUNTU USN-2894-1
[security-announce] openSUSE-SU-2016:0531-1: important: Security update lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:0531
PostgreSQL: Documentation: 9.5: Release 9.4.6 www.postgresql.org
text/html
URL Logo CONFIRM www.postgresql.org/docs/current/static/release-9-4-6.html
PostgreSQL Bugs Let Remote Users Deny Service and Let Remote Authenticated Users Gain Elevated Privileges - SecurityTracker www.securitytracker.com
text/html
URL Logo SECTRACK 1035005
PostgreSQL: Documentation: 9.5: Release 9.2.15 www.postgresql.org
text/html
URL Logo CONFIRM www.postgresql.org/docs/current/static/release-9-2-15.html
PostgreSQL: Documentation: 9.5: Release 9.1.20 www.postgresql.org
text/html
URL Logo CONFIRM www.postgresql.org/docs/current/static/release-9-1-20.html
[security-announce] SUSE-SU-2016:0677-1: important: Security update for lists.opensuse.org
text/html
URL Logo SUSE SUSE-SU-2016:0677
Debian -- Security Information -- DSA-3476-1 postgresql-9.4 www.debian.org
Depreciated Link
text/html
URL Logo DEBIAN DSA-3476
PostgreSQL: Documentation: 9.5: Release 9.3.11 www.postgresql.org
text/html
URL Logo CONFIRM www.postgresql.org/docs/current/static/release-9-3-11.html
PostgreSQL Integer Overflow and Privilege Escalation Vulnerabilities cve.report (archive)
text/html
URL Logo BID 83184
[security-announce] openSUSE-SU-2016:0578-1: important: Security update lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:0578

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
Operating
System
CanonicalUbuntu Linux12.04AllAllAll
Operating
System
CanonicalUbuntu Linux14.04AllAllAll
Operating
System
CanonicalUbuntu Linux15.10AllAllAll
Operating
System
CanonicalUbuntu Linux12.04AllAllAll
Operating
System
CanonicalUbuntu Linux14.04AllAllAll
Operating
System
CanonicalUbuntu Linux15.10AllAllAll
Operating
System
DebianDebian Linux7.0AllAllAll
Operating
System
DebianDebian Linux8.0AllAllAll
Operating
System
DebianDebian Linux7.0AllAllAll
Operating
System
DebianDebian Linux8.0AllAllAll
ApplicationPostgresqlPostgresql9.2AllAllAll
ApplicationPostgresqlPostgresql9.2.1AllAllAll
ApplicationPostgresqlPostgresql9.2.10AllAllAll
ApplicationPostgresqlPostgresql9.2.11AllAllAll
ApplicationPostgresqlPostgresql9.2.12AllAllAll
ApplicationPostgresqlPostgresql9.2.13AllAllAll
ApplicationPostgresqlPostgresql9.2.14AllAllAll
ApplicationPostgresqlPostgresql9.2.2AllAllAll
ApplicationPostgresqlPostgresql9.2.3AllAllAll
ApplicationPostgresqlPostgresql9.2.4AllAllAll
ApplicationPostgresqlPostgresql9.2.5AllAllAll
ApplicationPostgresqlPostgresql9.2.6AllAllAll
ApplicationPostgresqlPostgresql9.2.7AllAllAll
ApplicationPostgresqlPostgresql9.2.8AllAllAll
ApplicationPostgresqlPostgresql9.2.9AllAllAll
ApplicationPostgresqlPostgresql9.4AllAllAll
ApplicationPostgresqlPostgresql9.4.1AllAllAll
ApplicationPostgresqlPostgresql9.4.2AllAllAll
ApplicationPostgresqlPostgresql9.4.3AllAllAll
ApplicationPostgresqlPostgresql9.4.4AllAllAll
ApplicationPostgresqlPostgresql9.4.5AllAllAll
ApplicationPostgresqlPostgresql9.5AllAllAll
ApplicationPostgresqlPostgresql9.2AllAllAll
ApplicationPostgresqlPostgresql9.2.1AllAllAll
ApplicationPostgresqlPostgresql9.2.10AllAllAll
ApplicationPostgresqlPostgresql9.2.11AllAllAll
ApplicationPostgresqlPostgresql9.2.12AllAllAll
ApplicationPostgresqlPostgresql9.2.13AllAllAll
ApplicationPostgresqlPostgresql9.2.14AllAllAll
ApplicationPostgresqlPostgresql9.2.2AllAllAll
ApplicationPostgresqlPostgresql9.2.3AllAllAll
ApplicationPostgresqlPostgresql9.2.4AllAllAll
ApplicationPostgresqlPostgresql9.2.5AllAllAll
ApplicationPostgresqlPostgresql9.2.6AllAllAll
ApplicationPostgresqlPostgresql9.2.7AllAllAll
ApplicationPostgresqlPostgresql9.2.8AllAllAll
ApplicationPostgresqlPostgresql9.2.9AllAllAll
ApplicationPostgresqlPostgresql9.4AllAllAll
ApplicationPostgresqlPostgresql9.4.1AllAllAll
ApplicationPostgresqlPostgresql9.4.2AllAllAll
ApplicationPostgresqlPostgresql9.4.3AllAllAll
ApplicationPostgresqlPostgresql9.4.4AllAllAll
ApplicationPostgresqlPostgresql9.4.5AllAllAll
ApplicationPostgresqlPostgresql9.5AllAllAll
ApplicationPostgresqlPostgresqlAllAllAllAll
  • cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.11:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.12:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.13:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.14:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.7:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.11:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.12:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.13:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.14:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.7:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.2.9:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.4.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:9.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*: