PT-2025-3788 · Pgagent+2 · Pgagent+2

Wolfgang Frisch

·

Published

2025-01-03

·

Updated

2025-10-18

·

CVE-2025-0218

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions pgAgent versions prior to 4.2.3
Description The issue arises when pgAgent executes batch jobs, creating a script in a temporary directory before execution. In affected versions, an insufficiently seeded random number generator is used to generate the directory name. This allows a local attacker to potentially pre-create the directory, preventing pgAgent from executing jobs and disrupting scheduled tasks.
Recommendations For versions prior to 4.2.3, update to version 4.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the temporary directory used by pgAgent to minimize the risk of exploitation.

Fix

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

BDU:2025-12475
CVE-2025-0218
DLA-4338-1

Affected Products

Astra Linux
Debian
Pgagent