Medium severity5.5NVD Advisory· Published Nov 13, 2017· Updated May 13, 2026
CVE-2017-8806
CVE-2017-8806
Description
The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files.
Affected products
1- cpe:2.3:a:postgresql:postgresql:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- metadata.ftp-master.debian.org/changelogs/main/p/postgresql-common/postgresql-common_181+deb9u1_changelognvdBroken LinkIssue TrackingThird Party Advisory
- www.securityfocus.com/bid/101810nvdBroken LinkThird Party AdvisoryVDB Entry
- usn.ubuntu.com/usn/usn-3476-1/nvdIssue TrackingThird Party Advisory
- www.debian.org/security/2017/dsa-4029nvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.