Bug 1062538 - (CVE-2017-12172) VUL-0: CVE-2017-12172: postgresql: Start scripts permit database administrator to modify root-owned files
(CVE-2017-12172)
VUL-0: CVE-2017-12172: postgresql: Start scripts permit database administrato...
Status: RESOLVED INVALID
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Reinhard Max
Security Team bot
CVSSv3:SUSE:CVE-2017-12172:7.3:(AV:L/...
:
Depends on:
Blocks: CVE-2017-14798
  Show dependency treegraph
 
Reported: 2017-10-10 11:43 UTC by Marcus Meissner
Modified: 2018-01-23 23:55 UTC (History)
2 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 6 Johannes Segitz 2017-10-11 09:22:24 UTC
(In reply to Reinhard Max from comment #5)
yes, that is okay. 

I would like to assign one of our CVEs for the init script issue to track it. I opened bsc#1062722 for that
Comment 9 Reinhard Max 2017-10-13 09:18:42 UTC
Given that we now have a new bug and CVE for our problem, I guess we can close this one to which we are not vulnerable, right?
Comment 10 Johannes Segitz 2017-10-13 09:56:05 UTC
(In reply to Reinhard Max from comment #9)
yes, we can close it
Comment 11 Alexander Bergmann 2017-12-15 08:24:27 UTC
Making bug report public.

https://www.postgresql.org/docs/9.4/static/release-9-4-15.html
Comment 12 Swamp Workflow Management 2018-01-12 17:09:22 UTC
SUSE-SU-2018:0077-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1062538,1067844
CVE References: CVE-2017-12172,CVE-2017-15098
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    postgresql94-libs-9.4.15-0.23.10.1
SUSE Linux Enterprise Server 11-SP4 (src):    postgresql94-9.4.15-0.23.10.1, postgresql94-libs-9.4.15-0.23.10.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    postgresql94-9.4.15-0.23.10.1, postgresql94-libs-9.4.15-0.23.10.1
Comment 13 Swamp Workflow Management 2018-01-12 20:12:29 UTC
SUSE-SU-2018:0081-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1062538,1067844
CVE References: CVE-2017-12172,CVE-2017-15098
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    postgresql94-libs-9.4.15-21.13.1
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src):    postgresql94-9.4.15-21.13.1
SUSE Linux Enterprise Server 12-SP2 (src):    postgresql94-9.4.15-21.13.1
SUSE Linux Enterprise Desktop 12-SP2 (src):    postgresql94-9.4.15-21.13.1
Comment 14 Swamp Workflow Management 2018-01-15 14:15:07 UTC
openSUSE-SU-2018:0095-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1062538,1067844
CVE References: CVE-2017-12172,CVE-2017-15098
Sources used:
openSUSE Leap 42.3 (src):    postgresql94-9.4.15-15.1, postgresql94-libs-9.4.15-15.1
openSUSE Leap 42.2 (src):    postgresql94-9.4.15-9.12.1, postgresql94-libs-9.4.15-9.12.1