Vulnerability CVE-2017-15098


Published: 2017-11-22

Description:
Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.

Type:

CWE-200

(Information Exposure)

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.5/10
4.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
Partial
Affected software
Postgresql -> Postgresql 
Debian -> Debian linux 

 References:
http://www.securityfocus.com/bid/101781
http://www.securitytracker.com/id/1039752
https://access.redhat.com/errata/RHSA-2018:2511
https://access.redhat.com/errata/RHSA-2018:2566
https://www.debian.org/security/2017/dsa-4027
https://www.debian.org/security/2017/dsa-4028
https://www.postgresql.org/about/news/1801/
https://www.postgresql.org/support/security/

Copyright 2024, cxsecurity.com

 

Back to Top