PT-2013-6352 · Openssl+4 · Openssl+7
Marko Kreen
·
Publicado
1970-01-01
·
Atualizado
2024-06-15
·
CVE-2013-1900
CVSS v2.0
8.5
Alta
| Vetor | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PostgreSQL versions 8.4.x through 8.4.16
PostgreSQL versions 9.0.x through 9.0.12
PostgreSQL versions 9.1.x through 9.1.8
PostgreSQL versions 9.2.x through 9.2.3
libpq5 versions (affected versions not specified)
libpq5-32bit versions (affected versions not specified)
libecpg6 versions (affected versions not specified)
Description
The issue affects the generation of random numbers by the contrib/pgcrypto functions in PostgreSQL when using OpenSSL. This may allow remote authenticated users to have an unspecified impact. The vulnerability can be exploited remotely by an attacker who has passed the authentication procedure, potentially leading to a breach of confidentiality, integrity, and availability of protected information.
Recommendations
For PostgreSQL versions 8.4.x through 8.4.16, update to version 8.4.17 or later.
For PostgreSQL versions 9.0.x through 9.0.12, update to version 9.0.13 or later.
For PostgreSQL versions 9.1.x through 9.1.8, update to version 9.1.9 or later.
For PostgreSQL versions 9.2.x through 9.2.3, update to version 9.2.4 or later.
For libpq5, libpq5-32bit, and libecpg6, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Centos
Openssl
Postgresql
Red Hat
Suse
Libecpg6
Libpq5
Libpq5-32Bit