漏洞类别:Ubuntu
漏洞等级:
漏洞信息
It was discovered that PostgreSQL allowed the use of empty passwords in some authentication methods, contrary to expected behaviour.
It was discovered that PostgreSQL incorrectly handled the pg_user_mappings catalog view.
It was discovered that PostgreSQL incorrectly handled lo_put() permissions.
漏洞危害
A remote attacker could use an empty password to authenticate to servers that were believed to have password login disabled. (CVE-2017-7546)
A remote attacker without server privileges could possibly use this issue to obtain certain passwords. (CVE-2017-7547)
A remote attacker could possibly use this issue to change the data in a large object. (CVE-2017-7548)
解决方案
Refer to Ubuntu advisory USN-3390-1 for affected packages and patching details, or update with your package manager.
Patch:
Following are links for downloading patches to fix the vulnerabilities:
USN-3390-1: 14.04 (Kylin) on src (postgresql-9.3)
0daybank
文章评论