EulerOS 2.0 SP1 : posrgresql (EulerOS-SA-2017-1215)
Medium Nessus Plugin ID 103073
SynopsisThe remote EulerOS host is missing multiple security updates.
DescriptionAccording to the versions of the posrgresql packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities :
- It was found that some selectivity estimation functions did not check user privileges before providing information from pg_statistic, possibly leaking information. A non-administrative database user could use this flaw to steal some information from tables they are otherwise not allowed to access.
- It was found that the pg_user_mappings view could disclose information about user mappings to a foreign database to non-administrative database users. A database user with USAGE privilege for this mapping could, when querying the view, obtain user mapping data, such as the username and password used to connect to the foreign database. (CVE-2017-7486)
Note that Tenable Network Security has extracted the preceding description block directly from the EulerOS security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
SolutionUpdate the affected posrgresql packages.