CVE-2016-0766
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privileges…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privileges via unspecified vectors.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.11% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- postgresql/postgresql · canonical/ubuntu linux · debian/debian linux
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00049.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00052.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00054.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00056.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00016.htmlMailing List, Third Party Advisory
- http://www.debian.org/security/2016/dsa-3475Third Party Advisory
- http://www.debian.org/security/2016/dsa-3476Third Party Advisory
- http://www.postgresql.org/about/news/1644/Vendor Advisory
- http://www.postgresql.org/docs/current/static/release-9-1-20.htmlVendor Advisory
- http://www.postgresql.org/docs/current/static/release-9-2-15.htmlVendor Advisory
- http://www.postgresql.org/docs/current/static/release-9-3-11.htmlVendor Advisory
- http://www.postgresql.org/docs/current/static/release-9-4-6.htmlVendor Advisory
- http://www.postgresql.org/docs/current/static/release-9-5-1.htmlVendor Advisory
- http://www.securityfocus.com/bid/83184Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035005Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2894-1Third Party Advisory
- https://security.gentoo.org/glsa/201701-33Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00049.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00052.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00054.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00056.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00016.htmlMailing List, Third Party Advisory
- http://www.debian.org/security/2016/dsa-3475Third Party Advisory
- http://www.debian.org/security/2016/dsa-3476Third Party Advisory
- http://www.postgresql.org/about/news/1644/Vendor Advisory
- http://www.postgresql.org/docs/current/static/release-9-1-20.htmlVendor Advisory
- http://www.postgresql.org/docs/current/static/release-9-2-15.htmlVendor Advisory
- http://www.postgresql.org/docs/current/static/release-9-3-11.htmlVendor Advisory
- http://www.postgresql.org/docs/current/static/release-9-4-6.htmlVendor Advisory
- http://www.postgresql.org/docs/current/static/release-9-5-1.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.