Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3165

Опубликовано: 22 мая 2015
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.

A double-free flaw was found in the way PostgreSQL handled connections. An unauthenticated attacker could possibly exploit this flaw to crash the PostgreSQL backend by disconnecting at approximately the same time as the authentication time out was triggered.

Отчет

Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This flaw has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5postgresqlAffected
CloudForms Management Engine 5postgresql92-postgresqlAffected
Red Hat Enterprise Linux 5postgresqlAffected
Red Hat Enterprise Linux 5postgresql84Affected
Red Hat Satellite 5.7postgresql92Affected
Red Hat Enterprise Linux 6postgresqlFixedRHSA-2015:119429.06.2015
Red Hat Enterprise Linux 7postgresqlFixedRHSA-2015:119429.06.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6postgresql92-postgresqlFixedRHSA-2015:119529.06.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-postgresql94-postgresqlFixedRHSA-2015:119629.06.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSpostgresql92-postgresqlFixedRHSA-2015:119529.06.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1221537postgresql: double-free after authentication timeout

EPSS

Процентиль: 91%
0.07299
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.

nvd
около 10 лет назад

Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.

debian
около 10 лет назад

Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9. ...

github
около 3 лет назад

Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.

fstec
около 10 лет назад

Уязвимость операционной системы Debian GNU\Linux, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 91%
0.07299
Низкий

5 Medium

CVSS2