Lucene search

K
kasperskyKaspersky LabKLA11147
HistoryNov 09, 2017 - 12:00 a.m.

KLA11147 Multiple vulnerabilities in PostgreSQL

2017-11-0900:00:00
Kaspersky Lab
threats.kaspersky.com
51

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

AI Score

7.5

Confidence

High

EPSS

0.008

Percentile

81.3%

Multiple serious vulnerabilities have been found in PostgreSQL. Vulnerabilities in core server and contrib module components can be exploit remotely to gain privileges.

Original advisories

Security Information

Exploitation

Public exploits exist for this vulnerability.

Related products

PostgreSQL

CVE list

CVE-2017-12172 high

CVE-2017-15098 critical

CVE-2017-15099 high

Solution

Update to the latest version

Download PostgreSQL

Impacts

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

Affected Products

  • PostgreSQL 9.2 earlier than 9.2.24PostgreSQL 9.3 earlier than 9.3.20PostgreSQL 9.5 earlier than 9.5.10PostgreSQL 9.6 earlier than 9.6.6PostgreSQL 10 earlier than 10.1

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

AI Score

7.5

Confidence

High

EPSS

0.008

Percentile

81.3%