Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5288

Опубликовано: 08 окт. 2015
Источник: redhat
CVSS2: 4
EPSS Низкий

Описание

The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via a "too-short" salt.

A memory leak error was discovered in the crypt() function of the pgCrypto extension. An authenticated attacker could possibly use this flaw to disclose a limited amount of the server memory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5postgresqlWill not fix
Red Hat Enterprise Linux 5postgresql84Will not fix
Red Hat Satellite 5postgresql92-postgresqlAffected
Red Hat Enterprise Linux 6postgresqlFixedRHSA-2015:208118.11.2015
Red Hat Enterprise Linux 7postgresqlFixedRHSA-2015:207819.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-postgresql94-postgresqlFixedRHSA-2015:207718.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6postgresql92-postgresqlFixedRHSA-2015:208318.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSrh-postgresql94-postgresqlFixedRHSA-2015:207718.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSpostgresql92-postgresqlFixedRHSA-2015:208318.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSrh-postgresql94-postgresqlFixedRHSA-2015:207718.11.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-131->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1270306postgresql: limited memory disclosure flaw in crypt()

EPSS

Процентиль: 93%
0.08949
Низкий

4 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via a "too-short" salt.

nvd
больше 10 лет назад

The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via a "too-short" salt.

debian
больше 10 лет назад

The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9. ...

suse-cvrf
около 10 лет назад

Security update for postgresql91

github
почти 4 года назад

The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via a "too-short" salt.

EPSS

Процентиль: 93%
0.08949
Низкий

4 Medium

CVSS2