CVE-2017-8806 PUBLISHED

The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files.

EPSS 0.17% · 37.8th percentile

Risk Scores

EPSS Score
0.17%
37.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSpostgresql-common0, 169git1, 170
Ubuntu:14.04:LTSpostgresql-common154, 0, 154ubuntu1

Timeline

References

Open in Interactive Console →