5
CVSSv2

CVE-2015-3167

Published: 20/11/2019 Updated: 22/11/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

contrib/pgcrypto in PostgreSQL prior to 9.0.20, 9.1.x prior to 9.1.16, 9.2.x prior to 9.2.11, 9.3.x prior to 9.3.7, and 9.4.x prior to 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for malicious users to obtain the key via a brute force attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql

debian debian linux 7.0

debian debian linux 8.0

debian debian linux 9.0

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 14.10

canonical ubuntu linux 15.04

Vendor Advisories

Several vulnerabilities have been found in PostgreSQL-94, a SQL database system CVE-2015-3165 (Remote crash) SSL clients disconnecting just before the authentication timeout expires can cause the server to crash CVE-2015-3166 (Information exposure) The replacement implementation of snprintf() failed to check for errors reported ...
Several vulnerabilities have been found in PostgreSQL-91, a SQL database system CVE-2015-3165 (Remote crash) SSL clients disconnecting just before the authentication timeout expires can cause the server to crash CVE-2015-3166 (Information exposure) The replacement implementation of snprintf() failed to check for errors r ...
A double-free flaw was found in the connection handling An unauthenticated attacker could exploit this flaw to crash the PostgreSQL back end by disconnecting at approximately the same time as the authentication time out is triggered (CVE-2015-3165) It was discovered that PostgreSQL did not properly check the return values of certain standard libr ...