Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5289

Опубликовано: 08 окт. 2015
Источник: redhat
CVSS2: 4.3

Описание

Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.

A stack overflow flaw was discovered in the way the PostgreSQL core server processed certain JSON or JSONB input. An authenticated attacker could possibly use this flaw to crash the server backend by sending specially crafted JSON or JSONB input.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5postgresqlNot affected
Red Hat Enterprise Linux 5postgresql84Not affected
Red Hat Enterprise Linux 6postgresqlNot affected
Red Hat JBoss Enterprise Web Server 1postgresqlNot affected
Red Hat Satellite 5.7postgresql92-postgresqlAffected
Red Hat Enterprise Linux 7postgresqlFixedRHSA-2015:207819.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-postgresql94-postgresqlFixedRHSA-2015:207718.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6postgresql92-postgresqlFixedRHSA-2015:208318.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSrh-postgresql94-postgresqlFixedRHSA-2015:207718.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSpostgresql92-postgresqlFixedRHSA-2015:208318.11.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-131->CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=1270312postgresql: stack overflow DoS when parsing json or jsonb inputs

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.

nvd
около 10 лет назад

Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.

debian
около 10 лет назад

Multiple stack-based buffer overflows in json parsing in PostgreSQL be ...

github
больше 3 лет назад

Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.

fstec
около 10 лет назад

Уязвимости системы управления базами данных PostgreSQL, позволяющие нарушителю вызвать отказ в обслуживании

4.3 Medium

CVSS2