PT-2015-2594 · Postgresql+4 · Postgresql+4

Josh Kupershmidt

·

Publicado

2015-10-08

·

Atualizado

2024-06-15

·

CVE-2015-5288

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions PostgreSQL versions prior to 9.0.23 PostgreSQL versions 9.1.x prior to 9.1.19 PostgreSQL versions 9.2.x prior to 9.2.14 PostgreSQL versions 9.3.x prior to 9.3.10 PostgreSQL versions 9.4.x prior to 9.4.5
Description The issue is related to the crypt function in the contrib/pgcrypto component of the PostgreSQL database management system, which lacks protection of service data. This can be exploited by a remote attacker to cause a denial of service, such as a server crash, or to read arbitrary server memory via a "too-short" salt. A memory leak in the crypt() function is also mentioned.
Recommendations For versions prior to 9.0.23, update to version 9.0.23 or later. For versions 9.1.x prior to 9.1.19, update to version 9.1.19 or later. For versions 9.2.x prior to 9.2.14, update to version 9.2.14 or later. For versions 9.3.x prior to 9.3.10, update to version 9.3.10 or later. For versions 9.4.x prior to 9.4.5, update to version 9.4.5 or later.

Correção

DoS

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-11959
CESA-2015_2078
CESA-2015_2081
CVE-2015-5288
DLA-329-1
DSA-3374-1
DSA-3475-1
MGASA-2015-0420
OPENSUSE-SU-2024:10030-1
OPENSUSE-SU-2024:10256-1
OPENSUSE-SU-2024:10273-1
RHSA-2015:2077
RHSA-2015:2078
RHSA-2015:2081
RHSA-2015:2083
RHSA-2015_2078
RHSA-2015_2081
SUSE-OU-2015:1847-1
SUSE-SU-2015:1821-1
SUSE-SU-2015_1821-1
SUSE-SU-2016:0389-1
SUSE-SU-2016:0482-1
SUSE-SU-2016:0677-1
SUSE-SU-2016_0389-1
SUSE-SU-2016_0482-1
USN-2772-1

Produtos afetados

Centos
Postgresql
Red Hat
Suse
Ubuntu