6.8
CVSSv2

CVE-2013-0255

Published: 13/02/2013 Updated: 20/10/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C

Vulnerability Summary

PostgreSQL 9.2.x prior to 9.2.3, 9.1.x prior to 9.1.8, 9.0.x prior to 9.0.12, 8.4.x prior to 8.4.16, and 8.3.x prior to 8.3.23 does not properly declare the enum_recv function in backend/utils/adt/enum.c, which causes it to be invoked with incorrect arguments and allows remote authenticated users to cause a denial of service (server crash) or read sensitive process memory via a crafted SQL command, which triggers an array index error and an out-of-bounds read.

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql 8.3.16

postgresql postgresql 8.3.17

postgresql postgresql 8.3.20

postgresql postgresql 8.3.8

postgresql postgresql 8.3.21

postgresql postgresql 8.3.22

postgresql postgresql 8.3.2

postgresql postgresql 8.3.1

postgresql postgresql 8.3.19

postgresql postgresql 8.3.18

postgresql postgresql 8.3.6

postgresql postgresql 8.3.5

postgresql postgresql 8.3.12

postgresql postgresql 8.3.9

postgresql postgresql 8.3.11

postgresql postgresql 8.3.14

postgresql postgresql 8.3.7

postgresql postgresql 8.3.15

postgresql postgresql 8.3.4

postgresql postgresql 8.3.3

postgresql postgresql 8.3.10

postgresql postgresql 8.3.13

postgresql postgresql 8.3

postgresql postgresql 8.4.6

postgresql postgresql 8.4

postgresql postgresql 8.4.14

postgresql postgresql 8.4.15

postgresql postgresql 8.4.13

postgresql postgresql 8.4.10

postgresql postgresql 8.4.8

postgresql postgresql 8.4.9

postgresql postgresql 8.4.1

postgresql postgresql 8.4.11

postgresql postgresql 8.4.7

postgresql postgresql 8.4.4

postgresql postgresql 8.4.12

postgresql postgresql 8.4.5

postgresql postgresql 8.4.2

postgresql postgresql 8.4.3

postgresql postgresql 9.0.2

postgresql postgresql 9.0.6

postgresql postgresql 9.0.9

postgresql postgresql 9.0.4

postgresql postgresql 9.0.5

postgresql postgresql 9.0.7

postgresql postgresql 9.0.1

postgresql postgresql 9.0.11

postgresql postgresql 9.0

postgresql postgresql 9.0.8

postgresql postgresql 9.0.3

postgresql postgresql 9.0.10

postgresql postgresql 9.1

postgresql postgresql 9.1.5

postgresql postgresql 9.1.4

postgresql postgresql 9.1.3

postgresql postgresql 9.1.2

postgresql postgresql 9.1.7

postgresql postgresql 9.1.1

postgresql postgresql 9.1.6

Vendor Advisories

Synopsis Moderate: postgresql and postgresql84 security update Type/Severity Security Advisory: Moderate Topic Updated postgresql and postgresql84 packages that fix two security issuesare now available for Red Hat Enterprise Linux 5 and 6The Red Hat Security Response Team has rated this update as having mo ...
PostgreSQL could be made to crash if it received specially crafted input ...
Sumit Soni discovered that PostgreSQL, an object-relational SQL database, could be forced to crash when an internal function was called with invalid arguments, resulting in denial of service For the stable distribution (squeeze), this problem has been fixed in version 8416-0squeeze1 For the testing distribution (wheezy), this problem has been f ...
An array index error, leading to a heap-based out-of-bounds buffer read flaw, was found in the way PostgreSQL performed certain error processing using enumeration types An unprivileged database user could issue a specially crafted SQL query that, when processed by the server component of the PostgreSQL service, would lead to a denial of service (d ...