PT-2013-6352 · Openssl+4 · Openssl+7

Marko Kreen

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2013-1900

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PostgreSQL versions 8.4.x through 8.4.16 PostgreSQL versions 9.0.x through 9.0.12 PostgreSQL versions 9.1.x through 9.1.8 PostgreSQL versions 9.2.x through 9.2.3 libpq5 versions (affected versions not specified) libpq5-32bit versions (affected versions not specified) libecpg6 versions (affected versions not specified)
Description The issue affects the generation of random numbers by the contrib/pgcrypto functions in PostgreSQL when using OpenSSL. This may allow remote authenticated users to have an unspecified impact. The vulnerability can be exploited remotely by an attacker who has passed the authentication procedure, potentially leading to a breach of confidentiality, integrity, and availability of protected information.
Recommendations For PostgreSQL versions 8.4.x through 8.4.16, update to version 8.4.17 or later. For PostgreSQL versions 9.0.x through 9.0.12, update to version 9.0.13 or later. For PostgreSQL versions 9.1.x through 9.1.8, update to version 9.1.9 or later. For PostgreSQL versions 9.2.x through 9.2.3, update to version 9.2.4 or later. For libpq5, libpq5-32bit, and libecpg6, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04511
BDU:2015-04512
BDU:2015-04513
BDU:2015-04514
CESA-2013_1475
CVE-2013-1900
DSA-2657-1
DSA-2658-1
OPENSUSE-SU-2013_0627-1
OPENSUSE-SU-2013_0628-1
OPENSUSE-SU-2013_0635-1
OPENSUSE-SU-2024:10030-1
OPENSUSE-SU-2024:10256-1
OPENSUSE-SU-2024:10273-1
RHSA-2013:1475
RHSA-2013_1475

Affected Products

Centos
Openssl
Postgresql
Red Hat
Suse
Libecpg6
Libpq5
Libpq5-32Bit