Описание
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra-legacy/trusty | DNE | |
precise | ignored | end of life |
precise/esm | DNE | precise was needs-triage |
trusty | DNE | |
trusty/esm | DNE | |
upstream | needs-triage | |
utopic | DNE | |
vivid | DNE | |
vivid/stable-phone-overlay | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [9.1.16-0ubuntu0.14.04]] |
precise | released | 9.1.16-0ubuntu0.12.04 |
precise/esm | not-affected | 9.1.16-0ubuntu0.12.04 |
trusty | released | 9.1.16-0ubuntu0.14.04 |
trusty/esm | DNE | trusty was released [9.1.16-0ubuntu0.14.04] |
upstream | released | 9.1.16 |
utopic | DNE | |
vivid | DNE | |
vivid/stable-phone-overlay | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra-legacy/trusty | not-affected | 9.3.7-0ubuntu0.14.04 |
precise | DNE | |
precise/esm | DNE | |
trusty | released | 9.3.7-0ubuntu0.14.04 |
trusty/esm | not-affected | 9.3.7-0ubuntu0.14.04 |
upstream | released | 9.3.7 |
utopic | DNE | |
vivid | DNE | |
vivid/stable-phone-overlay | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra-legacy/trusty | DNE | |
precise | DNE | |
precise/esm | DNE | |
trusty | DNE | |
trusty/esm | DNE | |
upstream | released | 9.4.2 |
utopic | released | 9.4.2-0ubuntu0.14.10 |
vivid | released | 9.4.2-0ubuntu0.15.04 |
vivid/stable-phone-overlay | DNE |
Показывать по
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2 ...
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
5 Medium
CVSS2
7.5 High
CVSS3