PostgreSQL make_oidjoins_check Arbitrary File Overwrite

low Nessus Plugin ID 15417

Synopsis

The remote service is vulnerable to an unspecified flaw.

Description

The remote PostgreSQL server, according to its version number, is vulnerable to an unspecified insecure temporary file creation flaw, which may allow a local attacker to overwrite arbitrary files with the privileges of the application.

Solution

Upgrade to newer version of this software.

Plugin Details

Severity: Low

ID: 15417

File Name: postgresql_tempfile.nasl

Version: 1.18

Type: remote

Family: Databases

Published: 10/4/2004

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Low

Base Score: 2.1

Temporal Score: 1.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: cpe:/a:postgresql:postgresql

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 10/18/2004

Reference Information

CVE: CVE-2004-0977

BID: 11295