CVE-2014-8161: Medium severity postgresql vulnerability
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2014-8161.
What is the severity of CVE-2014-8161?
The severity of CVE-2014-8161 is medium.
How does CVE-2014-8161 impact PostgreSQL?
CVE-2014-8161 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message in PostgreSQL versions before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1.
What is the affected software for CVE-2014-8161?
The affected software for CVE-2014-8161 includes PostgreSQL versions before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1.
How can I fix CVE-2014-8161?
To fix CVE-2014-8161, you should update your PostgreSQL installation to version 9.0.19, 9.1.15, 9.2.10, 9.3.6, or 9.4.1.