Lucene search

K
kasperskyKaspersky LabKLA10592
HistoryMay 28, 2015 - 12:00 a.m.

KLA10592 Denial of service vulnerability in PostgreSQL

2015-05-2800:00:00
Kaspersky Lab
threats.kaspersky.com
26

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

9.7 High

AI Score

Confidence

High

0.085 Low

EPSS

Percentile

94.5%

Multiple serious vulnerabilities have been found in PostgreSQL. Malicious users can exploit these vulnerabilities to cause denial of service or conduct some other impact.

Below is a complete list of vulnerabilities

  1. Double free vulnerability can be exploited remotely via SSL session manipulations;
  2. Multiple errors can be exploited remotely via vectors related to pgcrypto and other unknown vectors.

Original advisories

PostrgeSQL blog entry

Related products

PostgreSQL

CVE list

CVE-2015-3165 warning

Solution

Update to the latest version

Get PostgreSQL

Impacts

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

Affected Products

  • PostgreSQL versions earlier than 9.0.20PostgreSQL 9.1 versions earlier than 9.1.16PostgreSQL 9.2 versions earlier than 9.2.11PostgreSQL 9.3 versions earlier than 9.3.7PostgreSQL 9.4 versions earlier than 9.4.2

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

9.7 High

AI Score

Confidence

High

0.085 Low

EPSS

Percentile

94.5%