CVE-2018-1053
Summary
| CVE | CVE-2018-1053 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-09 14:29:00 UTC |
| Updated | 2019-10-09 23:38:00 UTC |
| Description | In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under umask which was in effect when the user invoked pg_upgrade, and not under 0077 which is normally used for other temporary files. This can allow an authenticated attacker to read or modify the one file, which may contain encrypted or unencrypted database passwords. The attack is infeasible if a directory mode blocks the attacker searching the current working directory or if the prevailing umask blocks the attacker opening the file. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| [SECURITY] [DLA-1271-1] postgresql-9.1 security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Malformed Request |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| PostgreSQL: PostgreSQL 10.2, 9.6.7, 9.5.11, 9.4.16, and 9.3.21 released! |
CONFIRM |
www.postgresql.org |
Patch, Release Notes, Third Party Advisory |
| USN-3564-1: PostgreSQL vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500530 Alpine Linux Security Update for postgresql
- 501998 Alpine Linux Security Update for postgresql14
- 502764 Alpine Linux Security Update for postgresql15
- 504297 Alpine Linux Security Update for postgresql14