Re: PostgreSQL 2018-05-10 Security Update Release

Поиск
Список
Период
Сортировка
От Magnus Hagander
Тема Re: PostgreSQL 2018-05-10 Security Update Release
Дата
Msg-id CABUevEwMAR9019bJiZxq4o6VtEMzzmtwfJbX=FBOCWjrnh2Neg@mail.gmail.com
обсуждение исходный текст
Ответ на RE: PostgreSQL 2018-05-10 Security Update Release  (Huong Dangminh <huo-dangminh@ys.jp.nec.com>)
Ответы RE: PostgreSQL 2018-05-10 Security Update Release  (Huong Dangminh <huo-dangminh@ys.jp.nec.com>)
Список pgsql-bugs


On Fri, May 25, 2018 at 4:00 AM, Huong Dangminh <huo-dangminh@ys.jp.nec.com> wrote:
Hi,

> -----Original Message-----
> From: Stephen Frost [mailto:sfrost@postgresql.org]
> Sent: Thursday, May 10, 2018 10:37 PM
> To: pgsql-announce@lists.postgresql.org
> Subject: PostgreSQL 2018-05-10 Security Update Release
>
> Security Issues
> ---------------
>
> One security vulnerability has been closed by this release:
>
> * CVE-2018-1115: Too-permissive access control list on function
> pg_logfile_rotate()
>
> * Security Page: https://www.postgresql.org/support/security/

Thanks for the announcement.
I think "Component & CVSS v3 Base Score" column for "CVE-2018-1115" was wrong.
The Base Score appears 0.0 but it should be 4.2.

So link to "nist" should be update as below?
- https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N
+ https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L

And the Base Metrics also need to change like?
- AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N
+ AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L

Or am I missing something?

It seems RedHat have changed the CVSS vector from the one that we submitted to them. The PostgreSQL Security Team assigned the score and vector as is listed on the PostgreSQL website, so that is the correct one as standing.

I have pinged the RedHat team to see if they did this intentionally,or if it was a mistake. 


--

В списке pgsql-bugs по дате отправления:

Предыдущее
От: Huong Dangminh
Дата:
Сообщение: RE: PostgreSQL 2018-05-10 Security Update Release
Следующее
От: PG Bug reporting form
Дата:
Сообщение: BUG #15208: COALESCE with CTE returns NULL