### [CVE-2017-8806](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8806) ![](https://img.shields.io/static/v1?label=Product&message=PostgreSQL-related%20scripts%20that%20are%20specific%20to%20Debian%20and%20Ubuntu&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=handled%20symbolic%20links%20insecurely&color=brighgreen) ### Description The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files. ### POC #### Reference No PoCs from references. #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/NeXTLinux/vunnel - https://github.com/anchore/vunnel - https://github.com/khulnasoft-lab/vulnlist - https://github.com/renovate-bot/NeXTLinux-_-vunnel