Lucene search

K
postgresqlPostgreSQL Global Development GroupPOSTGRESQL:CVE-2014-0064
HistoryMar 31, 2014 - 2:58 p.m.

Vulnerability in core server (CVE-2014-0064)

2014-03-3114:58:15
PostgreSQL Global Development Group
www.postgresql.org
619

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.038

Percentile

91.9%

Potential buffer overruns due to integer overflow in size calculations.

Affected configurations

Vulners
Node
postgresqlpostgresqlRange<9.0.16
OR
postgresqlpostgresqlRange<9.3.3
OR
postgresqlpostgresqlRange<8.4.20
OR
postgresqlpostgresqlRange<9.2.7
OR
postgresqlpostgresqlRange<9.1.12
VendorProductVersionCPE
postgresqlpostgresql*cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.038

Percentile

91.9%