First published: Wed Nov 20 2019(Updated: )
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
PostgreSQL | <9.0.20 | |
PostgreSQL | >=9.1<9.1.16 | |
PostgreSQL | >=9.2<9.2.11 | |
PostgreSQL | >=9.3<9.3.7 | |
PostgreSQL | >=9.4<9.4.2 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =14.10 | |
Ubuntu Linux | =15.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3167 is a vulnerability in PostgreSQL versions before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 that allows attackers to obtain encryption keys via a brute force attack.
The severity of CVE-2015-3167 is high, with a CVSS score of 7.5.
To fix CVE-2015-3167, you should update your PostgreSQL installation to version 9.0.20, 9.1.16, 9.2.11, 9.3.7, or 9.4.2.
Yes, you can find more information about CVE-2015-3167 in the following references: http://ubuntu.com/usn/usn-2621-1, http://www.debian.org/security/2015/dsa-3269, http://www.debian.org/security/2015/dsa-3270.
The CWE ID for CVE-2015-3167 is CWE-200.