CVE-2015-3165: Double Free
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3165?
CVE-2015-3165 is classified as a denial of service vulnerability due to a double free issue in PostgreSQL.
How do I fix CVE-2015-3165?
To remediate CVE-2015-3165, upgrade PostgreSQL to the latest version that is not affected: 9.0.20, 9.1.16, 9.2.11, 9.3.7, or 9.4.2 and later.
What versions of PostgreSQL are affected by CVE-2015-3165?
CVE-2015-3165 affects PostgreSQL versions prior to 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2.
Can CVE-2015-3165 be exploited remotely?
Yes, CVE-2015-3165 can be exploited remotely by attackers to cause a crash in PostgreSQL.
What systems are vulnerable to CVE-2015-3165?
Systems with affected versions of PostgreSQL running on various distributions like Ubuntu and Debian are vulnerable to CVE-2015-3165.