Bug 993453 (CVE-2016-5424) - VUL-0: CVE-2016-5424 : postgresql: privilege escalation via crafted database and role names
Summary: VUL-0: CVE-2016-5424 : postgresql: privilege escalation via crafted database ...
Status: RESOLVED FIXED
Alias: CVE-2016-5424
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/171851/
Whiteboard: CVSSv2:SUSE:CVE-2016-5424:6.6:(AV:L/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-08-12 08:33 UTC by Victor Pereira
Modified: 2018-11-07 16:28 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2016-08-12 08:33:26 UTC
rh#1364002

It was found that PostgreSQL client programs mishandle database and role names containing newlines, carriage returns, double quotes, or backslashes. By crafting such an object name, roles with the CREATEDB or CREATEROLE option could escalate their privileges to superuser when a superuser next executes maintenance with a vulnerable program. Vulnerable programs include pg_dumpall, pg_upgrade, vacuumdb, reindexdb, and clusterdb.


References:
https://bugzilla.redhat.com/show_bug.cgi?id=1364002
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5424
http://www.debian.org/security/2016/dsa-3646
Comment 2 Andreas Stieger 2016-08-12 12:12:29 UTC
Affected versions: 9.5, 9.4, 9.3, 9.2, 9.1
Upstream fixed in: 9.5.4, 9.4.9, 9.3.14, 9.2.18, 9.1.23
Comment 3 Reinhard Max 2016-09-22 16:33:36 UTC
Packages were submitted to 13.2, SLE11-SP1 and SLE12 by Fabian Weiss, but for some reason the automatism that normally posts them here does not work.
Comment 4 Swamp Workflow Management 2016-09-29 15:11:08 UTC
SUSE-SU-2016:2414-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 973660,993453,993454
CVE References: CVE-2016-5423,CVE-2016-5424
Sources used:
SUSE Linux Enterprise Server for SAP 12 (src):    postgresql93-9.3.14-19.2
SUSE Linux Enterprise Server 12-LTSS (src):    postgresql93-9.3.14-19.2
Comment 5 Swamp Workflow Management 2016-09-29 15:11:52 UTC
SUSE-SU-2016:2415-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 973660,993453,993454
CVE References: CVE-2016-5423,CVE-2016-5424
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    postgresql94-libs-9.4.9-14.1
SUSE Linux Enterprise Server 12-SP1 (src):    postgresql94-9.4.9-14.1, postgresql94-libs-9.4.9-14.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    postgresql94-9.4.9-14.1, postgresql94-libs-9.4.9-14.1
Comment 6 Swamp Workflow Management 2016-09-29 17:11:49 UTC
SUSE-SU-2016:2418-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 993453,993454
CVE References: CVE-2016-5423,CVE-2016-5424
Sources used:
SUSE Manager 2.1 (src):    postgresql94-9.4.9-0.19.1
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    postgresql94-libs-9.4.9-0.19.1
SUSE Linux Enterprise Server 11-SP4 (src):    postgresql94-9.4.9-0.19.1, postgresql94-libs-9.4.9-0.19.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    postgresql94-9.4.9-0.19.1, postgresql94-libs-9.4.9-0.19.1
Comment 7 Swamp Workflow Management 2016-09-30 16:11:36 UTC
openSUSE-SU-2016:2425-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 993453,993454
CVE References: CVE-2016-5423,CVE-2016-5424
Sources used:
openSUSE 13.2 (src):    postgresql93-9.3.14-2.13.1, postgresql93-libs-9.3.14-2.13.1
Comment 8 Swamp Workflow Management 2016-10-06 13:09:51 UTC
openSUSE-SU-2016:2464-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 973660,993453,993454
CVE References: CVE-2016-5423,CVE-2016-5424
Sources used:
openSUSE Leap 42.1 (src):    postgresql94-9.4.9-7.1, postgresql94-libs-9.4.9-7.1
Comment 10 Swamp Workflow Management 2017-04-15 16:09:51 UTC
openSUSE-SU-2017:1021-1: An update that solves two vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1029547,973660,993453,993454
CVE References: CVE-2016-5423,CVE-2016-5424
Sources used:
openSUSE Leap 42.2 (src):    postgresql93-9.3.14-5.5.1, postgresql93-libs-9.3.14-5.5.1
openSUSE Leap 42.1 (src):    postgresql93-9.3.14-8.1, postgresql93-libs-9.3.14-8.1