RHSA-2018:3816HighCVSS 8.8

Red Hat Security Advisory: CloudForms 4.6.6 security, bug fix and enhancement update

Published
December 13, 2018
Last Modified
August 4, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2018-1053 — postgresql: pg_upgrade creates file of sensitive metadata under prevailing umask CVE-2018-1058 — postgresql: Uncontrolled search path element in pg_dump and other client applications CVE-2018-10915 — postgresql: Certain host connection parameters defeat client-side security defenses CVE-2018-10925 — postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements

🎯 Affected products30

  • CloudForms Management Engine 5.9
  • cfme-0:5.9.6.5-3.el7cf.src as a component of CloudForms Management Engine 5.9
  • cfme-0:5.9.6.5-3.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
  • cfme-amazon-smartstate-0:5.9.6.5-2.el7cf.src as a component of CloudForms Management Engine 5.9
  • cfme-amazon-smartstate-0:5.9.6.5-2.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
  • cfme-appliance-0:5.9.6.5-1.el7cf.src as a component of CloudForms Management Engine 5.9
  • cfme-appliance-0:5.9.6.5-1.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
  • cfme-appliance-common-0:5.9.6.5-1.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
  • cfme-appliance-debuginfo-0:5.9.6.5-1.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
  • cfme-appliance-tools-0:5.9.6.5-1.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
  • cfme-debuginfo-0:5.9.6.5-3.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
  • cfme-gemset-0:5.9.6.5-2.el7cf.src as a component of CloudForms Management Engine 5.9
  • cfme-gemset-0:5.9.6.5-2.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
  • cfme-gemset-debuginfo-0:5.9.6.5-2.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
  • dbus-api-service-0:1.0.1-3.1.el7cf.src as a component of CloudForms Management Engine 5.9
  • dbus-api-service-0:1.0.1-3.1.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
  • httpd-configmap-generator-0:0.2.2-1.2.el7cf.src as a component of CloudForms Management Engine 5.9
  • httpd-configmap-generator-0:0.2.2-1.2.el7cf.x86_64 as a component of CloudForms Management Engine 5.9
  • postgresql96-0:9.6.10-1PGDG.el7at.src as a component of CloudForms Management Engine 5.9
  • postgresql96-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
  • postgresql96-contrib-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
  • postgresql96-debuginfo-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
  • postgresql96-devel-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
  • postgresql96-docs-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
  • postgresql96-libs-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
  • postgresql96-plperl-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
  • postgresql96-plpython-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
  • postgresql96-pltcl-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
  • postgresql96-server-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9
  • postgresql96-test-0:9.6.10-1PGDG.el7at.x86_64 as a component of CloudForms Management Engine 5.9

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 If the postgresql service is running, it will be automatically restarted after installing this update. After installing the updated packages, the httpd daemon will be restarted automatically. Workaround: Upstream suggests the following mitigation can be used to protect against this security flaw: https://wiki.postgresql.org/wiki/A_Guide_to_CVE-2018-1058:_Protect_Your_Search_Path

🔗 References (68)