PT-2015-2594 · Postgresql+4 · Postgresql+4

Josh Kupershmidt

·

Published

2015-10-08

·

Updated

2024-06-15

·

CVE-2015-5288

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions PostgreSQL versions prior to 9.0.23 PostgreSQL versions 9.1.x prior to 9.1.19 PostgreSQL versions 9.2.x prior to 9.2.14 PostgreSQL versions 9.3.x prior to 9.3.10 PostgreSQL versions 9.4.x prior to 9.4.5
Description The issue is related to the crypt function in the contrib/pgcrypto component of the PostgreSQL database management system, which lacks protection of service data. This can be exploited by a remote attacker to cause a denial of service, such as a server crash, or to read arbitrary server memory via a "too-short" salt. A memory leak in the crypt() function is also mentioned.
Recommendations For versions prior to 9.0.23, update to version 9.0.23 or later. For versions 9.1.x prior to 9.1.19, update to version 9.1.19 or later. For versions 9.2.x prior to 9.2.14, update to version 9.2.14 or later. For versions 9.3.x prior to 9.3.10, update to version 9.3.10 or later. For versions 9.4.x prior to 9.4.5, update to version 9.4.5 or later.

Fix

DoS

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11959
CESA-2015_2078
CESA-2015_2081
CVE-2015-5288
DLA-329-1
DSA-3374-1
DSA-3475-1
MGASA-2015-0420
OPENSUSE-SU-2024:10030-1
OPENSUSE-SU-2024:10256-1
OPENSUSE-SU-2024:10273-1
RHSA-2015:2077
RHSA-2015:2078
RHSA-2015:2081
RHSA-2015:2083
RHSA-2015_2078
RHSA-2015_2081
SUSE-OU-2015:1847-1
SUSE-SU-2015:1821-1
SUSE-SU-2015_1821-1
SUSE-SU-2016:0389-1
SUSE-SU-2016:0482-1
SUSE-SU-2016:0677-1
SUSE-SU-2016_0389-1
SUSE-SU-2016_0482-1
USN-2772-1

Affected Products

Centos
Postgresql
Red Hat
Suse
Ubuntu