← Back

CVE-2016-1255

nvd nist
Published: Dec 5, 2017Modified: May 13, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, in Ubuntu 14.04 LTS before 154ubuntu1.1, in Ubuntu 16.04 LTS before 173ubuntu0.1, in Ubuntu 17.04 before 179ubuntu0.1, and in Ubuntu 17.10 before 184ubuntu1.1 allows local users to gain root privileges via a symlink attack on a logfile in /var/log/postgresql.

Affected (184)

1 product
Postgresql Common
Configuration A
1 platform
Running on/withPlatform Versions
Debian
Debian Linux
Version 7.0
Configuration B
150 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Debian
Version 100
Version 101
Version 102
Version 103
Version 104
Version 105
Version 106
Version 107
Version 108
Version 109
Version 10
Version 110
Version 111
Version 112
Version 113
Version 114
Version 115
Version 116
Version 117
Version 118
Version 119
Version 11
Version 120
Version 121
Version 123
Version 12
Version 130
Version 131
Version 132
Version 133
Version 134
Version 135
Version 136
Version 137
Version 138
Version 139
Version 13
Version 140
Version 141
Version 142
Version 143
Version 144
Version 145
Version 146
Version 147
Version 14
Version 155
Version 156
Version 157
Version 158
Version 159
Version 15
Version 160
Version 161
Version 162
Version 163
Version 164
Version 16
Version 17
Version 18
Version 19
Version 1
Version 20
Version 21
Version 22
Version 23
Version 24
Version 25
Version 26
Version 27
Version 28
Version 29
Version 2
Version 30
Version 31
Version 32
Version 33
Version 34
Version 35
Version 36
Version 37
Version 38
Version 39
Version 3
Version 40
Version 41
Version 42
Version 43
Version 44
Version 45
Version 46
Version 47
Version 48
Version 49
Version 4
Version 50
Version 51
Version 52
Version 53
Version 54
Version 55
Version 56
Version 57
Version 58
Version 59
Version 5
Version 60
Version 61
Version 62
Version 63
Version 64
Version 65
Version 66
Version 67
Version 68
Version 69
Version 6
Version 70
Version 71
Version 72
Version 73
Version 74
Version 75
Version 76
Version 77
Version 78
Version 79
Version 7
Version 80
Version 81
Version 82
Version 83
Version 84
Version 85
Version 86
Version 87
Version 88
Version 89
Version 8
Version 90
Version 91
Version 92
Version 93
Version 94
Version 95
Version 96
Version 97
Version 98
Version 99
Version 9
Running on/withPlatform Versions
Debian
Debian Linux
Version 8.0
Configuration C
9 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Debian
Version 122
Version 122ubuntu1
Version 124
Version 125
Version 126
Version 127
Version 128
Version 129
Version 129ubuntu1
Running on/withPlatform Versions
Canonical
Ubuntu Linux
Version 12.04
Configuration D
9 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Debian
Version 148
Version 149
Version 150
Version 151
Version 152
Version 153
Version 153bzr1
Version 154
Version 154ubuntu1
Running on/withPlatform Versions
Canonical
Ubuntu Linux
Version 14.04
Configuration E
6 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Debian
Version 169git1
Version 170
Version 171
Version 172
Version 172ubuntu1
Version 173
Running on/withPlatform Versions
Canonical
Ubuntu Linux
Version 16.04
Configuration F
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Debian
Version 176+git1
Version 177git1
Version 177ubuntu1
Version 178
Running on/withPlatform Versions
Canonical
Ubuntu Linux
Version 17.04
Configuration G
6 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Debian
Version 179
Version 181
Version 181ubuntu1
Version 183
Version 184
Version 184ubuntu1
Running on/withPlatform Versions
Canonical
Ubuntu Linux
Version 17.10

References (8)

Source: security@debian.org
Issue TrackingThird Party Advisory
Source: security@debian.org
Issue TrackingThird Party Advisory
Source: security@debian.org
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.