CVE-2016-1255

7.8 HIGH
Published: December 05, 2017 Modified: May 13, 2026
View on NVD

Description

The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, in Ubuntu 14.04 LTS before 154ubuntu1.1, in Ubuntu 16.04 LTS before 173ubuntu0.1, in Ubuntu 17.04 before 179ubuntu0.1, and in Ubuntu 17.10 before 184ubuntu1.1 allows local users to gain root privileges via a symlink attack on a logfile in /var/log/postgresql.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.ubuntu.com/usn/USN-3476-1
Source: security@debian.org
Issue Tracking Third Party Advisory
http://www.ubuntu.com/usn/USN-3476-2
Source: security@debian.org
Issue Tracking Third Party Advisory
https://lists.debian.org/debian-lts-announce/2017/01/msg00002.html
Source: security@debian.org
Issue Tracking Vendor Advisory
http://www.ubuntu.com/usn/USN-3476-1
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Third Party Advisory
http://www.ubuntu.com/usn/USN-3476-2
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Third Party Advisory
https://anonscm.debian.org/cgit/pkg-postgresql/postgresql-common.git/commit/?id=c8989206ec360f199400c74f129f7b4cb878c1ee
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Patch Vendor Advisory
https://lists.debian.org/debian-lts-announce/2017/01/msg00002.html
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Vendor Advisory

8 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.8 / 10.0
EPSS (Exploit Probability)
0.0%
10th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

canonical debian