[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-0066Date: (C)2014-04-11   (M)2023-12-22


The chkpass extension in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly check the return value of the crypt library function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.0
Exploit Score: 8.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: SINGLE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
APPLE-SA-2014-10-16-3
DSA-2864
DSA-2865
RHSA-2014:0211
RHSA-2014:0221
RHSA-2014:0249
RHSA-2014:0469
USN-2120-1
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://support.apple.com/kb/HT6448
http://wiki.postgresql.org/wiki/20140220securityrelease
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
http://www.postgresql.org/about/news/1506/
https://support.apple.com/kb/HT6536
openSUSE-SU-2014:0345
openSUSE-SU-2014:0368

CWE    1
CWE-20
OVAL    12
oval:org.secpod.oval:def:33755
oval:org.secpod.oval:def:1600166
oval:org.secpod.oval:def:601218
oval:org.secpod.oval:def:701584
...

© SecPod Technologies