Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-15098

Опубликовано: 09 нояб. 2017
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.

Отчет

This issue affects the versions of rh-postgresql94-postgresql, rh-postgresql95-postgresql, and rh-postgresql96-postgresql as shipped with Red Hat Software Collections 3. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5postgresqlNot affected
Red Hat Enterprise Linux 5postgresql84Not affected
Red Hat Enterprise Linux 6postgresqlNot affected
Red Hat Enterprise Linux 7postgresqlNot affected
Red Hat Satellite 5postgresql92-postgresqlNot affected
Red Hat Software Collectionsrh-postgresql94-postgresqlWill not fix
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-postgresql95-postgresqlFixedRHSA-2018:251120.08.2018
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-postgresql96-postgresqlFixedRHSA-2018:256627.08.2018
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSrh-postgresql95-postgresqlFixedRHSA-2018:251120.08.2018
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSrh-postgresql96-postgresqlFixedRHSA-2018:256627.08.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1508820postgresql: Memory disclosure in JSON functions

EPSS

Процентиль: 74%
0.00841
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 7 лет назад

Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.

CVSS3: 8.1
nvd
больше 7 лет назад

Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.

CVSS3: 8.1
debian
больше 7 лет назад

Invalid json_populate_recordset or jsonb_populate_recordset function c ...

CVSS3: 8.1
github
около 3 лет назад

Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.

CVSS3: 8.1
fstec
почти 8 лет назад

Уязвимость реализации функций json_populate_recordset и jsonb_populate_recordset системы управления базами данных PostgreSQL, позволяющая нарушителю вызвать отказ в обслуживании или получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 74%
0.00841
Низкий

7.1 High

CVSS3