[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3155-1 postgresql-9.1 -- postgresql-9.1

ID: oval:org.secpod.oval:def:601949Date: (C)2015-02-13   (M)2023-12-18
Class: PATCHFamily: unix




Several vulnerabilities have been found in PostgreSQL-9.1, a SQL database system. CVE-2014-8161: Information leak A user with limited clearance on a table might have access to information in columns without SELECT rights on through server error messages. CVE-2015-0241: Out of boundaries read/write The function to_char might read/write past the end of a buffer. This might crash the server when a formatting template is processed. CVE-2015-0243: Buffer overruns in contrib/pgcrypto The pgcrypto module is vulnerable to stack buffer overrun that might crash the server. CVE-2015-0244: SQL command injection Emil Lenngren reported that an attacker can inject SQL commands when the synchronization between client and server is lost.

Platform:
Debian 7.0
Product:
postgresql-9.1
Reference:
DSA-3155-1
CVE-2014-8161
CVE-2015-0241
CVE-2015-0243
CVE-2015-0244
CVE    4
CVE-2014-8161
CVE-2015-0241
CVE-2015-0244
CVE-2015-0243
...
CPE    2
cpe:/a:postgresql:postgresql:9.1
cpe:/o:debian:debian_linux:7.x

© SecPod Technologies