SB2017112139 - Security restrictions bypass in postgresql (Alpine package)
Published: November 21, 2017
Security Bulletin ID
SB2017112139
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2017-15099)
The vulnerability allows a remote attacker to bypass security restrictions on a targeted system.The weakness exists due to improper security restrictions in the case of an arbiter specified by constraint name. A remote attacker can submit specially crafted INSERT requests and bypass security controls on the update path of 'INSERT ... ON CONFLICT DO UPDATE' function to conduct further attacks.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=5600c80ab97b0bed725ec1c24f981a765e54593b
- https://git.alpinelinux.org/aports/commit/?id=c2110f5a7667d71596172fb142d3a573bb958c83
- https://git.alpinelinux.org/aports/commit/?id=2b95c8929982c3ff86b48ffe921cf9ddff6aeebd
- https://git.alpinelinux.org/aports/commit/?id=5f580c412de14f7329bf77293a1c8bbce8a74d48
- https://git.alpinelinux.org/aports/commit/?id=11f619ccc8258df5fe391ff5162599bf0fde2df7
- https://git.alpinelinux.org/aports/commit/?id=1540930789e891ee25aa5c2849d92380be163c91
- https://git.alpinelinux.org/aports/commit/?id=65a4706f6e8f861c00b64188cc452941d250cf11
- https://git.alpinelinux.org/aports/commit/?id=a0becadf6b7996ef4da8b9da940a7238a71635d9
- https://git.alpinelinux.org/aports/commit/?id=35901eec6ff1b0e1f1f66d5cb3eac62eed9b99b2
- https://git.alpinelinux.org/aports/commit/?id=b8e11aff4c567c24f2087860929d7fc15d0e7e0e