Errata ID | 391 |
---|---|
Date | 2018-05-08 |
Source package | postgresql-common |
Fixed in version | 165+deb8u3A~4.2.3.201801251012 |
Description | This update addresses the following issue: * pg_ctlcluster, pg_createcluster, pg_upgradecluster: Use lchown instead of chown to mitigate privilege escalation via symlinks. (CVE-2017-8806) |
Additional notes | |
CVE ID | CVE-2017-8806 |
UCS Bug number | #45752 #45753 |