CVE-2025-0218 Affecting pgagent package, versions *


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.04% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN11-PGAGENT-8602910
  • published8 Jan 2025
  • disclosed7 Jan 2025

Introduced: 7 Jan 2025

NewCVE-2025-0218  (opens in a new tab)

How to fix?

There is no fixed version for Debian:11 pgagent.

NVD Description

Note: Versions mentioned in the description apply only to the upstream pgagent package and not the pgagent package as distributed by Debian. See How to fix? for Debian:11 relevant fixed versions and status.

When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, an insufficiently seeded random number generator is used when generating the directory name, leading to the possibility for a local attacker to pre-create the directory and thus prevent pgAgent from executing jobs, disrupting scheduled tasks.