Описание
PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random numbers, which might allow remote authenticated users to have an unspecified impact via vectors related to the "contrib/pgcrypto functions."
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
CloudForms Management Engine 5 | postgresql | Will not fix | ||
Red Hat Enterprise Linux 5 | postgresql | Will not fix | ||
CloudForms Management Engine 5.x | cfme | Fixed | RHEA-2013:1487 | 31.10.2013 |
CloudForms Management Engine 5.x | cfme-vnc-plugin | Fixed | RHEA-2013:1487 | 31.10.2013 |
CloudForms Management Engine 5.x | libdnet | Fixed | RHEA-2013:1487 | 31.10.2013 |
CloudForms Management Engine 5.x | lshw | Fixed | RHEA-2013:1487 | 31.10.2013 |
CloudForms Management Engine 5.x | netapp-manageability-sdk | Fixed | RHEA-2013:1487 | 31.10.2013 |
CloudForms Management Engine 5.x | open-vm-tools | Fixed | RHEA-2013:1487 | 31.10.2013 |
CloudForms Management Engine 5.x | postgresql92 | Fixed | RHEA-2013:1487 | 31.10.2013 |
CloudForms Management Engine 5.x | postgresql92-postgresql | Fixed | RHEA-2013:1487 | 31.10.2013 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random numbers, which might allow remote authenticated users to have an unspecified impact via vectors related to the "contrib/pgcrypto functions."
PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random numbers, which might allow remote authenticated users to have an unspecified impact via vectors related to the "contrib/pgcrypto functions."
PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13 ...
PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random numbers, which might allow remote authenticated users to have an unspecified impact via vectors related to the "contrib/pgcrypto functions."
ELSA-2013-1475: postgresql and postgresql84 security update (MODERATE)
EPSS
4.3 Medium
CVSS2