SB2018082019 - Improper access control in PostgreSQL



SB2018082019 - Improper access control in PostgreSQL

Published: August 20, 2018 Updated: July 17, 2020

Security Bulletin ID SB2018082019
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper access control (CVE-ID: CVE-2016-7048)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download software.


Remediation

Install update from vendor's website.