A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.
References
Link | Resource |
---|---|
https://www.suse.com/de-de/security/cve/CVE-2017-14798/ | Vendor Advisory |
https://bugzilla.suse.com/show_bug.cgi?id=1062722 | Issue Tracking |
http://lists.suse.com/pipermail/sle-security-updates/2017-November/003420.html | Issue Tracking Vendor Advisory |
https://www.exploit-db.com/exploits/45184/ |
Information
Published : 2018-03-01 12:29
Updated : 2019-10-02 17:03
NVD link : CVE-2017-14798
Mitre link : CVE-2017-14798
JSON object : View
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Products Affected
postgresql
- postgresql
suse
- suse_linux_enterprise_server