[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-0064Date: (C)2014-05-20   (M)2023-12-22


Multiple integer overflows in the path_in and other unspecified functions in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact and attack vectors, which trigger a buffer overflow. NOTE: this identifier has been SPLIT due to different affected versions; use CVE-2014-2669 for the hstore vector.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.5
Exploit Score: 8.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: SINGLE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECUNIA-61307
BID-65725
APPLE-SA-2014-10-16-3
DSA-2864
DSA-2865
RHSA-2014:0211
RHSA-2014:0221
RHSA-2014:0249
RHSA-2014:0469
USN-2120-1
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://support.apple.com/kb/HT6448
http://wiki.postgresql.org/wiki/20140220securityrelease
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
http://www.postgresql.org/about/news/1506/
http://www.postgresql.org/support/security/
https://bugzilla.redhat.com/show_bug.cgi?id=1065230
https://github.com/postgres/postgres/commit/31400a673325147e1205326008e32135a78b4d8a
https://support.apple.com/kb/HT6536
openSUSE-SU-2014:0345
openSUSE-SU-2014:0368

CPE    57
cpe:/a:postgresql:postgresql:8.4.7
cpe:/a:postgresql:postgresql:8.4.6
cpe:/a:postgresql:postgresql:8.4.9
cpe:/a:postgresql:postgresql:8.4.8
...
CWE    1
CWE-189
OVAL    13
oval:org.secpod.oval:def:1600166
oval:org.secpod.oval:def:33752
oval:org.secpod.oval:def:203041
oval:org.secpod.oval:def:203046
...

© SecPod Technologies