CVE-2018-1115: Opensuse Leap
Critical severity, CVSS 9.1. EPSS: 3.9% chance of exploitation in the next 30 days.
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.
Affected products
- Opensuse Leap: version 15.1 only
- PostgreSQL PostgreSQL: before 9.6.9 (fixed in 9.6.9); from 10.0, before 10.4 (fixed in 10.4)
Published 2018-05-10. Last modified 2026-10-08.