Lucene search

K
kasperskyKaspersky LabKLA10686
HistoryOct 08, 2015 - 12:00 a.m.

KLA10686 Multiple vulnerabilities in PostgreSQL

2015-10-0800:00:00
Kaspersky Lab
threats.kaspersky.com
18

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

8.7 High

AI Score

Confidence

High

0.028 Low

EPSS

Percentile

90.7%

Multiple serious vulnerabilities have been found in PostgreSQL. Malicious users can exploit these vulnerabilities to cause denial of service or obtain sensitive information.

Below is a complete list of vulnerabilities

  1. An unknown vulnerability can be exploited via a specially designed user input to cause denial of service;
  2. An unknown vulnerability at pgCrypto can be exploited to obtain sensitive information.

Technical details

Vulnerability (1) caused by erroneous json or jsonb construction from input.

(2) caused by crypt function and can be triggered via β€˜too-short’ salt to read arbitrary server memory.

Original advisories

Release note

Related products

PostgreSQL

CVE list

CVE-2015-5289 high

CVE-2015-5288 high

Solution

Update to the latest version

Get PostgreSQL

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

Affected Products

  • PostgreSQL versions earlier than 9.0.23PostgreSQL 9.1 versions earlier than 9.1.19PostgreSQL 9.2 versions earlier than 9.2.14PostgreSQL 9.3 versions earlier than 9.3.10PostgreSQL 9.4 versions earlier than 9.4.5

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

8.7 High

AI Score

Confidence

High

0.028 Low

EPSS

Percentile

90.7%