cve/2017/CVE-2017-8806.md

22 lines
1.0 KiB
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2017-8806](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8806)
![](https://img.shields.io/static/v1?label=Product&message=PostgreSQL-related%20scripts%20that%20are%20specific%20to%20Debian%20and%20Ubuntu&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=handled%20symbolic%20links%20insecurely&color=brighgreen)
### Description
The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/NeXTLinux/vunnel
- https://github.com/anchore/vunnel
- https://github.com/khulnasoft-lab/vulnlist
- https://github.com/renovate-bot/NeXTLinux-_-vunnel