Vulnerability CVE-2017-15097


Published: 2018-07-27

Description:
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.

Type:

CWE-59

(Improper Link Resolution Before File Access ('Link Following'))

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Redhat -> Enterprise linux desktop 
Redhat -> Enterprise linux server 
Redhat -> Enterprise linux server aus 
Redhat -> Enterprise linux server eus 
Redhat -> Enterprise linux workstation 

 References:
http://www.securitytracker.com/id/1039983
https://access.redhat.com/errata/RHSA-2017:3402
https://access.redhat.com/errata/RHSA-2017:3403
https://access.redhat.com/errata/RHSA-2017:3404
https://access.redhat.com/errata/RHSA-2017:3405
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15097

Copyright 2024, cxsecurity.com

 

Back to Top