Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-0773

Опубликовано: 11 фев. 2016
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regular expression.

An integer overflow flaw, leading to a heap-based buffer overflow, was found in the PostgreSQL handling code for regular expressions. A remote attacker could use a specially crafted regular expression to cause PostgreSQL to crash or possibly execute arbitrary code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5postgresqlAffected
CloudForms Management Engine 5postgresql92-postgresqlAffected
Red Hat Enterprise Linux 5postgresqlWill not fix
Red Hat Enterprise Linux 5postgresql84Will not fix
Red Hat Enterprise Linux 5tclNot affected
Red Hat Enterprise Linux 6plNot affected
Red Hat Enterprise Linux 6tclNot affected
Red Hat Enterprise Linux 7tclNot affected
Red Hat Satellite 5.7postgresql92Affected
Red Hat Software Collectionsrh-postgresql95-postgresqlAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1303832postgresql: case insensitive range handling integer overflow leading to buffer overflow

EPSS

Процентиль: 89%
0.0451
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regular expression.

CVSS3: 7.5
nvd
больше 9 лет назад

PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regular expression.

CVSS3: 7.5
debian
больше 9 лет назад

PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9. ...

CVSS3: 7.5
github
около 3 лет назад

PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regular expression.

oracle-oval
больше 9 лет назад

ELSA-2016-0347: postgresql security update (IMPORTANT)

EPSS

Процентиль: 89%
0.0451
Низкий

6.8 Medium

CVSS2