Bugzilla – Bug 1062538
VUL-0: CVE-2017-12172: postgresql: Start scripts permit database administrator to modify root-owned files
Last modified: 2018-01-23 23:55:20 UTC
(In reply to Reinhard Max from comment #5) yes, that is okay. I would like to assign one of our CVEs for the init script issue to track it. I opened bsc#1062722 for that
Given that we now have a new bug and CVE for our problem, I guess we can close this one to which we are not vulnerable, right?
(In reply to Reinhard Max from comment #9) yes, we can close it
Making bug report public. https://www.postgresql.org/docs/9.4/static/release-9-4-15.html
SUSE-SU-2018:0077-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1062538,1067844 CVE References: CVE-2017-12172,CVE-2017-15098 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): postgresql94-libs-9.4.15-0.23.10.1 SUSE Linux Enterprise Server 11-SP4 (src): postgresql94-9.4.15-0.23.10.1, postgresql94-libs-9.4.15-0.23.10.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): postgresql94-9.4.15-0.23.10.1, postgresql94-libs-9.4.15-0.23.10.1
SUSE-SU-2018:0081-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1062538,1067844 CVE References: CVE-2017-12172,CVE-2017-15098 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP2 (src): postgresql94-libs-9.4.15-21.13.1 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src): postgresql94-9.4.15-21.13.1 SUSE Linux Enterprise Server 12-SP2 (src): postgresql94-9.4.15-21.13.1 SUSE Linux Enterprise Desktop 12-SP2 (src): postgresql94-9.4.15-21.13.1
openSUSE-SU-2018:0095-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1062538,1067844 CVE References: CVE-2017-12172,CVE-2017-15098 Sources used: openSUSE Leap 42.3 (src): postgresql94-9.4.15-15.1, postgresql94-libs-9.4.15-15.1 openSUSE Leap 42.2 (src): postgresql94-9.4.15-9.12.1, postgresql94-libs-9.4.15-9.12.1