Lucene search

K
kasperskyKaspersky LabKLA10449
HistoryMar 31, 2014 - 12:00 a.m.

KLA10449 DoS vulnerability in PostgreSQL

2014-03-3100:00:00
Kaspersky Lab
threats.kaspersky.com
111

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.1 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

76.9%

Multiple integer overflows were found in PostgreSQL. By exploiting this vulnerability malicious users can cause denial of service and possible extract arbitrary code. This vulnerability can be exploited remotely via vectors related to hstore_recv, hstore_from_arrays, hstore_from_array and hstoreArrayToPairs.

Original advisories

Related products

PostgreSQL

CVE list

CVE-2014-2669 high

Solution

Update to latest version

Get PostgreSQL

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

Affected Products

  • PostgreSQL 9.0 versions earlier than 9.0.16PostgreSQL 9.1 versions earlier than 9.1.12PostgreSQL 9.2 versions earlier than 9.2.7PostgreSQL 9.3 versions earlier than 9.3.3

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.1 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

76.9%