Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-4054

Опубликовано: 23 мая 2017
Источник: debian
EPSS Низкий

Описание

PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before a startup packet.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pgbouncerfixed1.5.5-1package
pgbouncerfixed1.5.4-6+deb8u1jessiepackage
pgbouncerfixed1.5.2-4+deb7u1wheezypackage
pgbouncerno-dsasqueezepackage

Примечания

  • https://github.com/pgbouncer/pgbouncer/commit/edab5be6665b9e8de66c25ba527509b229468573 (master)

  • https://github.com/pgbouncer/pgbouncer/commit/74d6e5f7de5ec736f71204b7b422af7380c19ac5 (stable-1.5)

  • https://github.com/pgbouncer/pgbouncer/issues/42

  • https://www.openwall.com/lists/oss-security/2015/05/21/2

EPSS

Процентиль: 87%
0.03375
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before a startup packet.

CVSS3: 7.5
nvd
больше 8 лет назад

PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before a startup packet.

CVSS3: 7.5
github
больше 3 лет назад

PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before a startup packet.

EPSS

Процентиль: 87%
0.03375
Низкий