Micro Focus SUSE Linux Enterprise Server是英国Micro Focus公司的一套企业服务器版Linux操作系统。 Micro Focus SUSE Linux Enterprise Server 11-SP4中的postgresql init脚本存在竞争条件漏洞。攻击者可利用该漏洞访问postgresql账户,提升至root权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| suse | postgresql-init | unspecified ~ 9.4-0.5.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-14804 | package builds could use directory traversal to write outside of target area | |
| CVE-2017-7435 | libzypp accepts unsigned 3rd party repo without warning | |
| CVE-2017-7436 | libzypp accepts unsigned packages even when configured to check signatures | |
| CVE-2017-9268 | open-build-service retrigger / wipebinaries hitting the wrong project bypassing access per | |
| CVE-2017-9269 | lack of keypinning in libzypp could lead to repository switching | |
| CVE-2017-9270 | post-auth arbitrary file write on cryptctl server | |
| CVE-2017-9271 | proxy credentials written to log files by zypper | |
| CVE-2017-9274 | osc executes spec code during "osc commit" | |
| CVE-2017-9286 | nextcloud package security issues with /srv/www/htdocs |
No comments yet