Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5288

Опубликовано: 08 окт. 2015
Источник: redhat
CVSS2: 4
EPSS Низкий

Описание

The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via a "too-short" salt.

A memory leak error was discovered in the crypt() function of the pgCrypto extension. An authenticated attacker could possibly use this flaw to disclose a limited amount of the server memory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5postgresqlWill not fix
Red Hat Enterprise Linux 5postgresql84Will not fix
Red Hat JBoss Enterprise Web Server 1postgresqlNot affected
Red Hat Satellite 5.7postgresql92-postgresqlAffected
Red Hat Enterprise Linux 6postgresqlFixedRHSA-2015:208118.11.2015
Red Hat Enterprise Linux 7postgresqlFixedRHSA-2015:207819.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-postgresql94-postgresqlFixedRHSA-2015:207718.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6postgresql92-postgresqlFixedRHSA-2015:208318.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSrh-postgresql94-postgresqlFixedRHSA-2015:207718.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSpostgresql92-postgresqlFixedRHSA-2015:208318.11.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-131->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1270306postgresql: limited memory disclosure flaw in crypt()

EPSS

Процентиль: 87%
0.0333
Низкий

4 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 9 лет назад

The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via a "too-short" salt.

nvd
больше 9 лет назад

The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via a "too-short" salt.

debian
больше 9 лет назад

The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9. ...

suse-cvrf
больше 9 лет назад

Security update for postgresql91

github
около 3 лет назад

The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via a "too-short" salt.

EPSS

Процентиль: 87%
0.0333
Низкий

4 Medium

CVSS2

Уязвимость CVE-2015-5288