PublicDateAtUSN: 2017-11-09 Candidate: CVE-2017-8806 CRD: 2017-11-09 PublicDate: 2017-11-13 09:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8806 https://ubuntu.com/security/notices/USN-3476-1 https://ubuntu.com/security/notices/USN-3476-2 Description: The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files. Ubuntu-Description: Notes: mdeslaur> PostgreSQL will use CVE-2017-12172 for contrib/start-scripts mdeslaur> This is related to CVE-2016-1255 Bugs: https://bugs.launchpad.net/ubuntu/+source/postgresql-common/+bug/1727209 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N [5.5 MEDIUM] Patches_postgresql-common: upstream: https://anonscm.debian.org/cgit/pkg-postgresql/postgresql-common.git/commit/?id=8b4d0a889a8287181c4bdf46462db9b737a6e25d upstream_postgresql-common: needs-triage precise/esm_postgresql-common: released (129ubuntu1.2) trusty_postgresql-common: released (154ubuntu1.1) trusty/esm_postgresql-common: released (154ubuntu1.1) xenial_postgresql-common: released (173ubuntu0.1) esm-infra/xenial_postgresql-common: released (173ubuntu0.1) zesty_postgresql-common: released (179ubuntu0.1) artful_postgresql-common: released (184ubuntu1.1) devel_postgresql-common: released (188ubuntu1)