8.1
CVSSv3

CVE-2017-15098

Published: 22/11/2017 Updated: 28/08/2018
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:P

Vulnerability Summary

Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x prior to 10.1, 9.6.x prior to 9.6.6, 9.5.x prior to 9.5.10, 9.4.x prior to 9.4.15, and 9.3.x prior to 9.3.20 can crash the server or disclose a few bytes of server memory.

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql 9.6.4

postgresql postgresql 9.6.3

postgresql postgresql 9.5.5

postgresql postgresql 9.5.4

postgresql postgresql 9.4.12

postgresql postgresql 9.4.11

postgresql postgresql 9.4.4

postgresql postgresql 9.4.3

postgresql postgresql 9.4.2

postgresql postgresql 9.3.15

postgresql postgresql 9.3.14

postgresql postgresql 9.3.7

postgresql postgresql 9.3.6

postgresql postgresql 9.6.2

postgresql postgresql 9.6.1

postgresql postgresql 9.6

postgresql postgresql 9.5.3

postgresql postgresql 9.5.2

postgresql postgresql 9.4.10

postgresql postgresql 9.4.9

postgresql postgresql 9.4.1

postgresql postgresql 9.4

postgresql postgresql 9.3.13

postgresql postgresql 9.3.12

postgresql postgresql 9.3.5

postgresql postgresql 9.3.4

postgresql postgresql 9.5.9

postgresql postgresql 9.5.8

postgresql postgresql 9.5.1

postgresql postgresql 9.5

postgresql postgresql 9.4.8

postgresql postgresql 9.4.7

postgresql postgresql 9.3.19

postgresql postgresql 9.3.18

postgresql postgresql 9.3.11

postgresql postgresql 9.3.10

postgresql postgresql 9.3.3

postgresql postgresql 9.3.2

postgresql postgresql 10

postgresql postgresql 9.6.5

postgresql postgresql 9.5.7

postgresql postgresql 9.5.6

postgresql postgresql 9.4.14

postgresql postgresql 9.4.13

postgresql postgresql 9.4.6

postgresql postgresql 9.4.5

postgresql postgresql 9.3.17

postgresql postgresql 9.3.16

postgresql postgresql 9.3.9

postgresql postgresql 9.3.8

postgresql postgresql 9.3.1

postgresql postgresql 9.3

debian debian linux 8.0

Vendor Advisories

Synopsis Important: rh-postgresql96-postgresql security update Type/Severity Security Advisory: Important Topic An update for rh-postgresql96-postgresql is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnera ...
Synopsis Important: rh-postgresql95-postgresql security update Type/Severity Security Advisory: Important Topic An update for rh-postgresql95-postgresql is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnera ...
Privilege escalation flaws were found in the initialization scripts of PostgreSQL A remote attacker with access to the postgres user account could use these flaws to obtain root access on the server machine(CVE-2017-12172) INSERT ON CONFLICT DO UPDATE commands in PostgreSQL disclose table contents that the invoker lacks privilege to read Th ...
Privilege escalation flaws were found in the initialization scripts of PostgreSQL A remote attacker with access to the postgres user account could use these flaws to obtain root access on the server machine( CVE-2017-12172) Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL can crash the server or disclose a ...
Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10x before 101, 96x before 966, 95x before 9510, 94x before 9415, and 93x before 9320 can crash the server or disclose a few bytes of server memory ...
A denial of service and potential memory disclosure vulnerability has been discovered in PostgreSQL in the json_populate_recordset() and jsonb_populate_recordset() functions ...
For more information about PostgreSQL versioning, please visit the versioning page ...