CVE-2016-1255
Last modified
CVE-2016-1255 is a vulnerability of currently unknown severity. The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, in Ubuntu 14.04 LTS before 154ubuntu1.1, in Ubuntu 16.04 LTS before 173ubuntu0.1, in Ubuntu 17.04 before 179ubuntu0.1, and in Ubuntu 17.10 before 184ubuntu1.1 allows local users to gain root privileges via a symlink attack on a logfile in /var/log/postgresql.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, in Ubuntu 14.04 LTS before 154ubuntu1.1, in Ubuntu 16.04 LTS before 173ubuntu0.1, in Ubuntu 17.04 before 179ubuntu0.1, and in Ubuntu 17.10 before 184ubuntu1.1 allows local users to gain root privileges via a symlink attack on a logfile in /var/log/postgresql.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Debian | Postgresql-Common | 1 |
| Debian | Postgresql-Common | 2 |
| Debian | Postgresql-Common | 3 |
| Debian | Postgresql-Common | 4 |
| Debian | Postgresql-Common | 5 |
| Debian | Postgresql-Common | 6 |
| Debian | Postgresql-Common | 7 |
| Debian | Postgresql-Common | 8 |
| Debian | Postgresql-Common | 9 |
| Debian | Postgresql-Common | 10 |
| Debian | Postgresql-Common | 11 |
| Debian | Postgresql-Common | 12 |
| Debian | Postgresql-Common | 13 |
| Debian | Postgresql-Common | 14 |
| Debian | Postgresql-Common | 15 |
| Debian | Postgresql-Common | 16 |
| Debian | Postgresql-Common | 17 |
| Debian | Postgresql-Common | 18 |
| Debian | Postgresql-Common | 19 |
| Debian | Postgresql-Common | 20 |
| Debian | Postgresql-Common | 21 |
| Debian | Postgresql-Common | 22 |
| Debian | Postgresql-Common | 23 |
| Debian | Postgresql-Common | 24 |
| Debian | Postgresql-Common | 25 |
| Debian | Postgresql-Common | 26 |
| Debian | Postgresql-Common | 27 |
| Debian | Postgresql-Common | 28 |
| Debian | Postgresql-Common | 29 |
| Debian | Postgresql-Common | 30 |
| Debian | Postgresql-Common | 31 |
| Debian | Postgresql-Common | 32 |
| Debian | Postgresql-Common | 33 |
| Debian | Postgresql-Common | 34 |
| Debian | Postgresql-Common | 35 |
| Debian | Postgresql-Common | 36 |
| Debian | Postgresql-Common | 37 |
| Debian | Postgresql-Common | 38 |
| Debian | Postgresql-Common | 39 |
| Debian | Postgresql-Common | 40 |
| Debian | Postgresql-Common | 41 |
| Debian | Postgresql-Common | 42 |
| Debian | Postgresql-Common | 43 |
| Debian | Postgresql-Common | 44 |
| Debian | Postgresql-Common | 45 |
| Debian | Postgresql-Common | 46 |
| Debian | Postgresql-Common | 47 |
| Debian | Postgresql-Common | 48 |
| Debian | Postgresql-Common | 49 |
| Debian | Postgresql-Common | 50 |
Showing 50 of 184 affected configurations. See NVD for the full list.
References
- http://www.ubuntu.com/usn/USN-3476-1Issue Tracking, Third Party Advisory
- http://www.ubuntu.com/usn/USN-3476-2Issue Tracking, Third Party Advisory
- https://anonscm.debian.org/cgit/pkg-postgresql/postgresql-common.git/commit/?id=c8989206ec360f199400c74f129f7b4cb878c1eeIssue Tracking, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2017/01/msg00002.htmlIssue Tracking, Vendor Advisory
- http://www.ubuntu.com/usn/USN-3476-1Issue Tracking, Third Party Advisory
- http://www.ubuntu.com/usn/USN-3476-2Issue Tracking, Third Party Advisory
- https://anonscm.debian.org/cgit/pkg-postgresql/postgresql-common.git/commit/?id=c8989206ec360f199400c74f129f7b4cb878c1eeIssue Tracking, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2017/01/msg00002.htmlIssue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-1255?
How severe is CVE-2016-1255?
How do I fix CVE-2016-1255?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-1249The DBD::mysql module before 4.039 for Perl, when using serv…
- CVE-2016-1250Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-1251There is a vulnerability of type use-after-free affecting DB…
- CVE-2016-1252The apt package in Debian jessie before 1.0.9.8.4, in Debian…5.9
- CVE-2016-1253The most package in Debian wheezy before 5.0.0a-2.2, in Debi…
- CVE-2016-1254Tor before 0.2.8.12 might allow remote attackers to cause a …
- CVE-2016-1256Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-…
- CVE-2016-1257The Routing Engine in Juniper Junos OS 13.2R5 through 13.2R8…
- CVE-2016-1258Embedthis Appweb, as used in J-Web in Juniper Junos OS befor…
- CVE-2016-1260Juniper Junos OS before 13.2X51-D36, 14.1X53 before 14.1X53-…
- CVE-2016-1261J-Web does not validate certain input that may lead to cross…7.1
- CVE-2016-1262Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-…
Are you affected by CVE-2016-1255?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
