Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

fstec Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

BDU:2015-03115

ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 24 сСнт. 2002
Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: fstec
CVSS2: 7.5
EPSS Низкий

ОписаниС

ΠœΠ½ΠΎΠΆΠ΅ΡΡ‚Π²Π΅Π½Π½Ρ‹Π΅ уязвимости ΠΏΠ°ΠΊΠ΅Ρ‚Π° ecpg ΠΎΠΏΠ΅Ρ€Π°Ρ†ΠΈΠΎΠ½Π½ΠΎΠΉ систСмы DebianΒ GNU/Linux, эксплуатация ΠΊΠΎΡ‚ΠΎΡ€Ρ‹Ρ… ΠΌΠΎΠΆΠ΅Ρ‚ привСсти ΠΊ Π½Π°Ρ€ΡƒΡˆΠ΅Π½ΠΈΡŽ ΠΊΠΎΠ½Ρ„ΠΈΠ΄Π΅Π½Ρ†ΠΈΠ°Π»ΡŒΠ½ΠΎΡΡ‚ΠΈ, цСлостности ΠΈ доступности Π·Π°Ρ‰ΠΈΡ‰Π°Π΅ΠΌΠΎΠΉ ΠΈΠ½Ρ„ΠΎΡ€ΠΌΠ°Ρ†ΠΈΠΈ. Эксплуатация уязвимостСй ΠΌΠΎΠΆΠ΅Ρ‚ Π±Ρ‹Ρ‚ΡŒ осущСствлСна ΡƒΠ΄Π°Π»Π΅Π½Π½ΠΎ

Π’Π΅Π½Π΄ΠΎΡ€

БообщСство свободного ΠΏΡ€ΠΎΠ³Ρ€Π°ΠΌΠΌΠ½ΠΎΠ³ΠΎ обСспСчСния

НаимСнованиС ПО

Debian GNU/Linux

ВСрсия ПО

Π΄ΠΎ 3.0 (Debian GNU/Linux)

Вип ПО

ΠžΠΏΠ΅Ρ€Π°Ρ†ΠΈΠΎΠ½Π½Π°Ρ систСма

ΠžΠΏΠ΅Ρ€Π°Ρ†ΠΈΠΎΠ½Π½Ρ‹Π΅ систСмы ΠΈ Π°ΠΏΠΏΠ°Ρ€Π°Ρ‚Π½Ρ‹Π΅ ΠΏΠ»Π°Ρ‚Ρ„ΠΎΡ€ΠΌΡ‹

-

Π£Ρ€ΠΎΠ²Π΅Π½ΡŒ опасности уязвимости

Высокий ΡƒΡ€ΠΎΠ²Π΅Π½ΡŒ опасности (базовая ΠΎΡ†Π΅Π½ΠΊΠ° CVSS 2.0 составляСт 7,5)

Π’ΠΎΠ·ΠΌΠΎΠΆΠ½Ρ‹Π΅ ΠΌΠ΅Ρ€Ρ‹ ΠΏΠΎ ΡƒΡΡ‚Ρ€Π°Π½Π΅Π½ΠΈΡŽ уязвимости

ΠŸΡ€ΠΎΠ±Π»Π΅ΠΌΠ° ΠΌΠΎΠΆΠ΅Ρ‚ Π±Ρ‹Ρ‚ΡŒ Ρ€Π΅ΡˆΠ΅Π½Π° ΠΎΠ±Π½ΠΎΠ²Π»Π΅Π½ΠΈΠ΅ΠΌ ΠΎΠΏΠ΅Ρ€Π°Ρ†ΠΈΠΎΠ½Π½ΠΎΠΉ систСмы Π΄ΠΎ ΡΠ»Π΅Π΄ΡƒΡŽΡ‰ΠΈΡ… вСрсий ΠΏΠ°ΠΊΠ΅Ρ‚ΠΎΠ² Π² зависимости ΠΎΡ‚ Π°Ρ€Ρ…ΠΈΡ‚Π΅ΠΊΡ‚ΡƒΡ€Ρ‹:
Debian GNU/Linux 3.0:
ppc:
courier-authpostgresql - 0.37.3-3.1
libecpg3 - 7.2.1-2woody2
libpgperl - 7.2.1-2woody2
libpgsql2 - 7.2.1-2woody2
libpgtcl - 7.2.1-2woody2
odbc-postgresql - 7.2.1-2woody2
pgaccess - 7.2.1-2woody2
postgresql - 7.2.1-2woody2
postgresql-client - 7.2.1-2woody2
postgresql-contrib - 7.2.1-2woody2
postgresql-dev - 7.2.1-2woody2
python-pygresql - 7.2.1-2woody2
s390x:
courier-authpostgresql - 0.37.3-3.1
libecpg3 - 7.2.1-2woody2
libpgperl - 7.2.1-2woody2
libpgsql2 - 7.2.1-2woody2
libpgtcl - 7.2.1-2woody2
odbc-postgresql - 7.2.1-2woody2
pgaccess - 7.2.1-2woody2
postgresql - 7.2.1-2woody2
postgresql-client - 7.2.1-2woody2
postgresql-contrib - 7.2.1-2woody2
postgresql-dev - 7.2.1-2woody2
python-pygresql - 7.2.1-2woody2
m68k:
courier-authpostgresql - 0.37.3-3.1
libecpg3 - 7.2.1-2woody2
libpgperl - 7.2.1-2woody2
libpgsql2 - 7.2.1-2woody2
libpgtcl - 7.2.1-2woody2
odbc-postgresql - 7.2.1-2woody2
pgaccess - 7.2.1-2woody2
postgresql - 7.2.1-2woody2
postgresql-client - 7.2.1-2woody2
postgresql-contrib - 7.2.1-2woody2
postgresql-dev - 7.2.1-2woody2
python-pygresql - 7.2.1-2woody2
i686:
courier-authpostgresql - 0.37.3-3.1
libecpg3 - 7.2.1-2woody2
libpgperl - 7.2.1-2woody2
libpgsql2 - 7.2.1-2woody2
libpgtcl - 7.2.1-2woody2
odbc-postgresql - 7.2.1-2woody2
pgaccess - 7.2.1-2woody2
postgresql - 7.2.1-2woody2
postgresql-client - 7.2.1-2woody2
postgresql-contrib - 7.2.1-2woody2
postgresql-dev - 7.2.1-2woody2
python-pygresql - 7.2.1-2woody2
hppa:
courier-authpostgresql - 0.37.3-3.1
libecpg3 - 7.2.1-2woody2
libpgperl - 7.2.1-2woody2
libpgsql2 - 7.2.1-2woody2
libpgtcl - 7.2.1-2woody2
odbc-postgresql - 7.2.1-2woody2
pgaccess - 7.2.1-2woody2
postgresql - 7.2.1-2woody2
postgresql-client - 7.2.1-2woody2
postgresql-contrib - 7.2.1-2woody2
postgresql-dev - 7.2.1-2woody2
python-pygresql - 7.2.1-2woody2
sparc:
courier-authpostgresql - 0.37.3-3.1
libecpg3 - 7.2.1-2woody2
libpgperl - 7.2.1-2woody2
libpgsql2 - 7.2.1-2woody2
libpgtcl - 7.2.1-2woody2
odbc-postgresql - 7.2.1-2woody2
pgaccess - 7.2.1-2woody2
postgresql - 7.2.1-2woody2
postgresql-client - 7.2.1-2woody2
postgresql-contrib - 7.2.1-2woody2
postgresql-dev - 7.2.1-2woody2
python-pygresql - 7.2.1-2woody2
alpha:
courier-authpostgresql - 0.37.3-3.1
libecpg3 - 7.2.1-2woody2
libpgperl - 7.2.1-2woody2
libpgsql2 - 7.2.1-2woody2
libpgtcl - 7.2.1-2woody2
odbc-postgresql - 7.2.1-2woody2
pgaccess - 7.2.1-2woody2
postgresql - 7.2.1-2woody2
postgresql-client - 7.2.1-2woody2
postgresql-contrib - 7.2.1-2woody2
postgresql-dev - 7.2.1-2woody2
python-pygresql - 7.2.1-2woody2
ia64:
courier-authpostgresql - 0.37.3-3.1
libecpg3 - 7.2.1-2woody2
libpgperl - 7.2.1-2woody2
libpgsql2 - 7.2.1-2woody2
libpgtcl - 7.2.1-2woody2
odbc-postgresql - 7.2.1-2woody2
pgaccess - 7.2.1-2woody2
postgresql - 7.2.1-2woody2
postgresql-client - 7.2.1-2woody2
postgresql-contrib - 7.2.1-2woody2
postgresql-dev - 7.2.1-2woody2
python-pygresql - 7.2.1-2woody2
mips:
courier-authpostgresql - 0.37.3-3.1
libecpg3 - 7.2.1-2woody2
libpgperl - 7.2.1-2woody2
libpgsql2 - 7.2.1-2woody2
libpgtcl - 7.2.1-2woody2
odbc-postgresql - 7.2.1-2woody2
pgaccess - 7.2.1-2woody2
postgresql - 7.2.1-2woody2
postgresql-client - 7.2.1-2woody2
postgresql-contrib - 7.2.1-2woody2
postgresql-dev - 7.2.1-2woody2
python-pygresql - 7.2.1-2woody2
noarch:
postgresql-doc - 7.2.1-2woody2
mipsel:
courier-authpostgresql - 0.37.3-3.1
libecpg3 - 7.2.1-2woody2
libpgperl - 7.2.1-2woody2
libpgsql2 - 7.2.1-2woody2
libpgtcl - 7.2.1-2woody2
odbc-postgresql - 7.2.1-2woody2
pgaccess - 7.2.1-2woody2
postgresql - 7.2.1-2woody2
postgresql-client - 7.2.1-2woody2
postgresql-contrib - 7.2.1-2woody2
postgresql-dev - 7.2.1-2woody2
python-pygresql - 7.2.1-2woody2
arm:
courier-authpostgresql - 0.37.3-3.1
libecpg3 - 7.2.1-2woody2
libpgperl - 7.2.1-2woody2
libpgsql2 - 7.2.1-2woody2
libpgtcl - 7.2.1-2woody2
odbc-postgresql - 7.2.1-2woody2
pgaccess - 7.2.1-2woody2
postgresql - 7.2.1-2woody2
postgresql-client - 7.2.1-2woody2
postgresql-contrib - 7.2.1-2woody2
postgresql-dev - 7.2.1-2woody2
python-pygresql - 7.2.1-2woody2
Debian GNU/Linux 2.2:
ppc:
ecpg - 6.5.3-27.2
libpgperl - 6.5.3-27.2
libpgsql2 - 6.5.3-27.2
libpgtcl - 6.5.3-27.2
odbc-postgresql - 6.5.3-27.2
pgaccess - 6.5.3-27.2
postgresql - 6.5.3-27.2
postgresql-client - 6.5.3-27.2
postgresql-contrib - 6.5.3-27.2
postgresql-dev - 6.5.3-27.2
postgresql-pl - 6.5.3-27.2
postgresql-test - 6.5.3-27.2
python-pygresql - 6.5.3-27.2
m68k:
ecpg - 6.5.3-27.2
libpgperl - 6.5.3-27.2
libpgsql2 - 6.5.3-27.2
libpgtcl - 6.5.3-27.2
odbc-postgresql - 6.5.3-27.2
pgaccess - 6.5.3-27.2
postgresql - 6.5.3-27.2
postgresql-client - 6.5.3-27.2
postgresql-contrib - 6.5.3-27.2
postgresql-dev - 6.5.3-27.2
postgresql-pl - 6.5.3-27.2
postgresql-test - 6.5.3-27.2
python-pygresql - 6.5.3-27.2
noarch:
postgresql-doc - 6.5.3-27.2
sparc:
ecpg - 6.5.3-27.2
libpgperl - 6.5.3-27.2
libpgsql2 - 6.5.3-27.2
libpgtcl - 6.5.3-27.2
odbc-postgresql - 6.5.3-27.2
pgaccess - 6.5.3-27.2
postgresql - 6.5.3-27.2
postgresql-client - 6.5.3-27.2
postgresql-contrib - 6.5.3-27.2
postgresql-dev - 6.5.3-27.2
postgresql-pl - 6.5.3-27.2
postgresql-test - 6.5.3-27.2
python-pygresql - 6.5.3-27.2
alpha:
ecpg - 6.5.3-27.2
libpgperl - 6.5.3-27.2
libpgsql2 - 6.5.3-27.2
libpgtcl - 6.5.3-27.2
odbc-postgresql - 6.5.3-27.2
pgaccess - 6.5.3-27.2
postgresql - 6.5.3-27.2
postgresql-client - 6.5.3-27.2
postgresql-contrib - 6.5.3-27.2
postgresql-dev - 6.5.3-27.2
postgresql-pl - 6.5.3-27.2
postgresql-test - 6.5.3-27.2
python-pygresql - 6.5.3-27.2
i686:
ecpg - 6.5.3-27.2
libpgperl - 6.5.3-27.2
libpgsql2 - 6.5.3-27.2
libpgtcl - 6.5.3-27.2
odbc-postgresql - 6.5.3-27.2
pgaccess - 6.5.3-27.2
postgresql - 6.5.3-27.2
postgresql-client - 6.5.3-27.2
postgresql-contrib - 6.5.3-27.2
postgresql-dev - 6.5.3-27.2
postgresql-pl - 6.5.3-27.2
postgresql-test - 6.5.3-27.2
python-pygresql - 6.5.3-27.2
arm:
ecpg - 6.5.3-27.2
libpgperl - 6.5.3-27.2
libpgsql2 - 6.5.3-27.2
libpgtcl - 6.5.3-27.2
odbc-postgresql - 6.5.3-27.2
pgaccess - 6.5.3-27.2
postgresql - 6.5.3-27.2
postgresql-client - 6.5.3-27.2
postgresql-contrib - 6.5.3-27.2
postgresql-dev - 6.5.3-27.2
postgresql-pl - 6.5.3-27.2
postgresql-test - 6.5.3-27.2
python-pygresql - 6.5.3-27.2

Бтатус уязвимости

ΠŸΠΎΠ΄Ρ‚Π²Π΅Ρ€ΠΆΠ΄Π΅Π½Π° ΠΏΡ€ΠΎΠΈΠ·Π²ΠΎΠ΄ΠΈΡ‚Π΅Π»Π΅ΠΌ

НаличиС эксплойта

Π”Π°Π½Π½Ρ‹Π΅ ΡƒΡ‚ΠΎΡ‡Π½ΡΡŽΡ‚ΡΡ

Π˜Π½Ρ„ΠΎΡ€ΠΌΠ°Ρ†ΠΈΡ ΠΎΠ± устранСнии

Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ устранСна

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 28%
0.00099
Низкий

7.5 High

CVSS2

БвязанныС уязвимости

redhat
большС 23 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad.

nvd
большС 23 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad.

debian
большС 23 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial o ...

github
ΠΏΠΎΡ‡Ρ‚ΠΈ 4 Π³ΠΎΠ΄Π° Π½Π°Π·Π°Π΄

Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad.

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 28%
0.00099
Низкий

7.5 High

CVSS2

Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ BDU:2015-03115