9.8
CVSSv3

CVE-2015-3166

Published: 20/11/2019 Updated: 22/11/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The snprintf implementation in PostgreSQL prior to 9.0.20, 9.1.x prior to 9.1.16, 9.2.x prior to 9.2.11, 9.3.x prior to 9.3.7, and 9.4.x prior to 9.4.2 does not properly handle system-call errors, which allows malicious users to obtain sensitive information or have other unspecified impact via unknown vectors, as demonstrated by an out-of-memory error.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql

debian debian linux 7.0

debian debian linux 8.0

debian debian linux 9.0

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 14.10

canonical ubuntu linux 15.04

Vendor Advisories

Several vulnerabilities have been found in PostgreSQL-94, a SQL database system CVE-2015-3165 (Remote crash) SSL clients disconnecting just before the authentication timeout expires can cause the server to crash CVE-2015-3166 (Information exposure) The replacement implementation of snprintf() failed to check for errors reported ...
Several vulnerabilities have been found in PostgreSQL-91, a SQL database system CVE-2015-3165 (Remote crash) SSL clients disconnecting just before the authentication timeout expires can cause the server to crash CVE-2015-3166 (Information exposure) The replacement implementation of snprintf() failed to check for errors r ...
A double-free flaw was found in the connection handling An unauthenticated attacker could exploit this flaw to crash the PostgreSQL back end by disconnecting at approximately the same time as the authentication time out is triggered (CVE-2015-3165) It was discovered that PostgreSQL did not properly check the return values of certain standard libr ...