Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5289

Опубликовано: 08 окт. 2015
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.

A stack overflow flaw was discovered in the way the PostgreSQL core server processed certain JSON or JSONB input. An authenticated attacker could possibly use this flaw to crash the server backend by sending specially crafted JSON or JSONB input.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5postgresqlNot affected
Red Hat Enterprise Linux 5postgresql84Not affected
Red Hat Enterprise Linux 6postgresqlNot affected
Red Hat JBoss Enterprise Web Server 1postgresqlNot affected
Red Hat Satellite 5.7postgresql92-postgresqlAffected
Red Hat Enterprise Linux 7postgresqlFixedRHSA-2015:207819.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-postgresql94-postgresqlFixedRHSA-2015:207718.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6postgresql92-postgresqlFixedRHSA-2015:208318.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSrh-postgresql94-postgresqlFixedRHSA-2015:207718.11.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSpostgresql92-postgresqlFixedRHSA-2015:208318.11.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-131->CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=1270312postgresql: stack overflow DoS when parsing json or jsonb inputs

EPSS

Процентиль: 91%
0.07453
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 9 лет назад

Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.

nvd
больше 9 лет назад

Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.

debian
больше 9 лет назад

Multiple stack-based buffer overflows in json parsing in PostgreSQL be ...

github
около 3 лет назад

Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.

fstec
больше 9 лет назад

Уязвимости системы управления базами данных PostgreSQL, позволяющие нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 91%
0.07453
Низкий

4.3 Medium

CVSS2