PT-2025-3788 · Pgagent+2 · Pgagent+2
Wolfgang Frisch
·
Published
2025-01-03
·
Updated
2025-10-18
·
CVE-2025-0218
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pgAgent versions prior to 4.2.3
Description
The issue arises when pgAgent executes batch jobs, creating a script in a temporary directory before execution. In affected versions, an insufficiently seeded random number generator is used to generate the directory name. This allows a local attacker to potentially pre-create the directory, preventing pgAgent from executing jobs and disrupting scheduled tasks.
Recommendations
For versions prior to 4.2.3, update to version 4.2.3 or later to resolve the issue.
As a temporary workaround, consider restricting access to the temporary directory used by pgAgent to minimize the risk of exploitation.
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Debian
Pgagent