CVE-2016-3065: Critical severity postgresql common vulnerability
The (1) brinpagetype and (2) brinmetapageinfo functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attackers to bypass intended access restrictions and consequently obtain sensitive server memory information or cause a denial of service (server crash) via a crafted bytea value in a BRIN index page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3065?
CVE-2016-3065 is considered to have a moderate severity level due to its potential impact on sensitive data and system stability.
How do I fix CVE-2016-3065?
To fix CVE-2016-3065, update PostgreSQL to version 9.5.2 or later to ensure that access restrictions are properly enforced.
What software versions are affected by CVE-2016-3065?
CVE-2016-3065 affects PostgreSQL versions 9.5 and 9.5.1.
What are the potential risks associated with CVE-2016-3065?
The risks associated with CVE-2016-3065 include unauthorized access to sensitive server memory and potential denial of service due to server crashes.
Can CVE-2016-3065 allow attackers to execute arbitrary code?
No, CVE-2016-3065 does not directly allow arbitrary code execution but can lead to sensitive information disclosure and service disruptions.