Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-0064
HistoryFeb 21, 2014 - 12:00 a.m.

CVE-2014-0064

2014-02-2100:00:00
ubuntu.com
ubuntu.com
15

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.038

Percentile

91.9%

Multiple integer overflows in the path_in and other unspecified functions
in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12,
9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users
to have unspecified impact and attack vectors, which trigger a buffer
overflow. NOTE: this identifier has been SPLIT due to different affected
versions; use CVE-2014-2669 for the hstore vector.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchpostgresql-8.4< 8.4.20-0ubuntu010.04UNKNOWN
ubuntu12.04noarchpostgresql-8.4< 8.4.22-0ubuntu0.12.04UNKNOWN
ubuntu12.04noarchpostgresql-9.1< 9.1.12-0ubuntu0.12.04UNKNOWN
ubuntu12.10noarchpostgresql-9.1< 9.1.12-0ubuntu0.12.10UNKNOWN
ubuntu13.10noarchpostgresql-9.1< 9.1.12-0ubuntu0.13.10UNKNOWN
ubuntu14.04noarchpostgresql-9.1< 9.1.12-1UNKNOWN
ubuntu14.04noarchpostgresql-9.3< 9.3.3-1UNKNOWN

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.038

Percentile

91.9%