Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3167

Опубликовано: 22 мая 2015
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.

It was discovered that the pgcrypto module could return different error messages when decrypting certain data with an incorrect key. This could potentially help an authenticated user to launch a possible cryptographic attack, although no suitable attack is currently known.

Отчет

Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This flaw has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5postgresqlAffected
CloudForms Management Engine 5postgresql92-postgresqlAffected
Red Hat Enterprise Linux 5postgresqlAffected
Red Hat Enterprise Linux 5postgresql84Affected
Red Hat Satellite 5.7postgresql92Affected
Red Hat Enterprise Linux 6postgresqlFixedRHSA-2015:119429.06.2015
Red Hat Enterprise Linux 7postgresqlFixedRHSA-2015:119429.06.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6postgresql92-postgresqlFixedRHSA-2015:119529.06.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-postgresql94-postgresqlFixedRHSA-2015:119629.06.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSpostgresql92-postgresqlFixedRHSA-2015:119529.06.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-209
https://bugzilla.redhat.com/show_bug.cgi?id=1221541postgresql: pgcrypto has multiple error messages for decryption with an incorrect key.

EPSS

Процентиль: 86%
0.02851
Низкий

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.

CVSS3: 7.5
nvd
больше 5 лет назад

contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.

CVSS3: 7.5
debian
больше 5 лет назад

contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2 ...

CVSS3: 7.5
github
около 3 лет назад

contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.

suse-cvrf
около 10 лет назад

Security update for postgresql93

EPSS

Процентиль: 86%
0.02851
Низкий

2.6 Low

CVSS2