4
CVSSv2

CVE-2014-0066

Published: 31/03/2014 Updated: 13/02/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 358
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

The chkpass extension in PostgreSQL prior to 8.4.20, 9.0.x prior to 9.0.16, 9.1.x prior to 9.1.12, 9.2.x prior to 9.2.7, and 9.3.x prior to 9.3.3 does not properly check the return value of the crypt library function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql 8.4.8

postgresql postgresql 9.0.11

postgresql postgresql 9.2.1

postgresql postgresql 9.1.4

postgresql postgresql 8.4.4

postgresql postgresql 8.4.1

postgresql postgresql 9.0.13

postgresql postgresql 9.3

postgresql postgresql 8.4.18

postgresql postgresql 9.0.7

postgresql postgresql 9.0.6

postgresql postgresql

postgresql postgresql 9.3.2

postgresql postgresql 8.4.9

postgresql postgresql 8.4.3

postgresql postgresql 9.2.6

postgresql postgresql 9.1

postgresql postgresql 8.4.10

postgresql postgresql 9.2.3

postgresql postgresql 9.0.10

postgresql postgresql 9.0.4

postgresql postgresql 8.4.11

postgresql postgresql 8.4.6

postgresql postgresql 9.1.9

postgresql postgresql 9.0.9

postgresql postgresql 9.1.5

postgresql postgresql 9.1.8

postgresql postgresql 8.4.17

postgresql postgresql 9.2

postgresql postgresql 9.1.2

postgresql postgresql 9.1.6

postgresql postgresql 8.4.15

postgresql postgresql 9.0.1

postgresql postgresql 9.2.4

postgresql postgresql 9.0.14

postgresql postgresql 9.1.7

postgresql postgresql 8.4.12

postgresql postgresql 9.1.3

postgresql postgresql 8.4.14

postgresql postgresql 9.0.3

postgresql postgresql 9.0

postgresql postgresql 9.3.1

postgresql postgresql 9.1.1

postgresql postgresql 9.0.2

postgresql postgresql 9.0.5

postgresql postgresql 9.0.12

postgresql postgresql 8.4.5

postgresql postgresql 9.1.10

postgresql postgresql 9.0.15

postgresql postgresql 9.2.5

postgresql postgresql 9.1.11

postgresql postgresql 8.4.7

postgresql postgresql 9.0.8

postgresql postgresql 8.4.2

postgresql postgresql 9.2.2

postgresql postgresql 8.4.16

postgresql postgresql 8.4.13

Vendor Advisories

Several security issues were fixed in PostgreSQL ...
Various vulnerabilities were discovered in PostgreSQL: CVE-2014-0060 Shore up GRANT WITH ADMIN OPTION restrictions (Noah Misch) Granting a role without ADMIN OPTION is supposed to prevent the grantee from adding or removing members from the granted role, but this restriction was easily bypassed by doing SET ROLE first The securit ...
Various vulnerabilities were discovered in PostgreSQL: CVE-2014-0060 Shore up GRANT WITH ADMIN OPTION restrictions (Noah Misch) Granting a role without ADMIN OPTION is supposed to prevent the grantee from adding or removing members from the granted role, but this restriction was easily bypassed by doing SET ROLE first The securit ...
Multiple stack-based buffer overflow flaws were found in the date/time implementation of PostgreSQL An authenticated database user could provide a specially crafted date/time value that, when processed, could cause PostgreSQL to crash or, potentially, execute arbitrary code with the permissions of the user running PostgreSQL (CVE-2014-0063) Multi ...
Multiple stack-based buffer overflow flaws were found in the date/time implementation of PostgreSQL An authenticated database user could provide a specially crafted date/time value that, when processed, could cause PostgreSQL to crash or, potentially, execute arbitrary code with the permissions of the user running PostgreSQL (CVE-2014-0063) Multi ...
The chkpass extension in PostgreSQL before 8420, 90x before 9016, 91x before 9112, 92x before 927, and 93x before 933 does not properly check the return value of the crypt library function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors ...