{"id":"CVE-2017-8806","details":"The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files.","modified":"2026-02-04T18:20:36.396618Z","published":"2017-11-13T09:29:00Z","related":["CGA-3vc3-x52g-9h99"],"references":[{"type":"ADVISORY","url":"http://metadata.ftp-master.debian.org/changelogs/main/p/postgresql-common/postgresql-common_181+deb9u1_changelog"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/101810"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/usn/usn-3476-1/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2017/dsa-4029"},{"type":"REPORT","url":"http://metadata.ftp-master.debian.org/changelogs/main/p/postgresql-common/postgresql-common_181+deb9u1_changelog"},{"type":"REPORT","url":"https://usn.ubuntu.com/usn/usn-3476-1/"},{"type":"REPORT","url":"https://www.debian.org/security/2017/dsa-4029"},{"type":"WEB","url":"http://metadata.ftp-master.debian.org/changelogs/main/p/postgresql-common/postgresql-common_181+deb9u1_changelog"},{"type":"WEB","url":"http://www.securityfocus.com/bid/101810"}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}]}