CVE-2017-7484
Public on 2017-05-12
Modified on 2017-06-06
Description
It was found that some selectivity estimation functions did not check user privileges before providing information from pg_statistic, possibly leaking information. A non-administrative database user could use this flaw to steal some information from tables they are otherwise not allowed to access.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 1 | postgresql92 | 2017-06-06 | ALAS-2017-838 | Fixed |
Amazon Linux 1 | postgresql93 | 2017-06-06 | ALAS-2017-839 | Fixed |
Amazon Linux 1 | postgresql94 | 2017-06-06 | ALAS-2017-839 | Fixed |
Amazon Linux 1 | postgresql95 | 2017-06-06 | ALAS-2017-839 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 4.3 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
NVD | CVSSv2 | 5.0 | AV:N/AC:L/Au:N/C:P/I:N/A:N |
NVD | CVSSv3 | 7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |