First published: Mon Jan 27 2020(Updated: )
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
PostgreSQL PostgreSQL | <9.0.19 | |
PostgreSQL PostgreSQL | >=9.1.0<9.1.15 | |
PostgreSQL PostgreSQL | >=9.2.0<9.2.10 | |
PostgreSQL PostgreSQL | >=9.3.0<9.3.6 | |
PostgreSQL PostgreSQL | >=9.4.0<9.4.1 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0243 is a vulnerability in PostgreSQL that allows remote authenticated users to cause a denial of service and possibly execute arbitrary code.
CVE-2015-0243 affects PostgreSQL versions before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1.
CVE-2015-0243 has a severity score of 8.8 (High).
To fix CVE-2015-0243, upgrade your PostgreSQL installation to version 9.0.19, 9.1.15, 9.2.10, 9.3.6, or 9.4.1.
You can find more information about CVE-2015-0243 on Debian's website at http://www.debian.org/security/2015/dsa-3155 and PostgreSQL's website at http://www.postgresql.org/about/news/1569/ and http://www.postgresql.org/docs/9.4/static/release-9-4-1.html.