Lucene search

K
osvGoogleOSV:DSA-3374-1
HistoryOct 19, 2015 - 12:00 a.m.

postgresql-9.4 - security update

2015-10-1900:00:00
Google
osv.dev
9

0.028 Low

EPSS

Percentile

90.7%

Several vulnerabilities have been found in PostgreSQL-9.4, a SQL
database system.

  • CVE-2015-5288
    Josh Kupershmidt discovered a vulnerability in the crypt() function
    in the pgCrypto extension. Certain invalid salt arguments can cause
    the server to crash or to disclose a few bytes of server memory.
  • CVE-2015-5289
    Oskari Saarenmaa discovered that json or jsonb input values
    constructed from arbitrary user input can crash the PostgreSQL
    server and cause a denial of service.

For the stable distribution (jessie), these problems have been fixed in
version 9.4.5-0+deb8u1.

For the testing distribution (stretch), these problems have been fixed
in version 9.4.5-1.

For the unstable distribution (sid), these problems have been fixed in
version 9.4.5-1.

We recommend that you upgrade your postgresql-9.4 packages.