CVE-2013-0255
PostgreSQL 9.2.x before 9.2.3, 9.1.x before 9.1.8, 9.0.x before 9.0.12, 8.4.x before 8.4.16, and 8.3.x before 8.3.23 does not properly declare the enum_recv function in backend/utils/adt/enum.c, which causes it to be invoked with incorrect arguments and…
Does this matter?
Lower severity and a low EPSS score (3.59%). Track it; it rarely justifies an emergency change on its own.
Description
PostgreSQL 9.2.x before 9.2.3, 9.1.x before 9.1.8, 9.0.x before 9.0.12, 8.4.x before 8.4.16, and 8.3.x before 8.3.23 does not properly declare the enum_recv function in backend/utils/adt/enum.c, which causes it to be invoked with incorrect arguments and allows remote authenticated users to cause a denial of service (server crash) or read sensitive process memory via a crafted SQL command, which triggers an array index error and an out-of-bounds read.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
- EPSS
- 3.59% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- postgresql/postgresql
- Source
- secalert@redhat.com
References
- http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098586.html
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00059.html
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00060.html
- http://osvdb.org/89935
- http://rhn.redhat.com/errata/RHSA-2013-1475.html
- http://secunia.com/advisories/51923Vendor Advisory
- http://secunia.com/advisories/52819
- http://securitytracker.com/id?1028092
- http://www.debian.org/security/2013/dsa-2630
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:142
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.postgresql.org/docs/8.3/static/release-8-3-23.html
- http://www.postgresql.org/docs/8.4/static/release-8-4-16.html
- http://www.postgresql.org/docs/9.0/static/release-9-0-12.html
- http://www.postgresql.org/docs/9.1/static/release-9-1-8.html
- http://www.postgresql.org/docs/9.2/static/release-9-2-3.html
- http://www.securityfocus.com/bid/57844
- http://www.ubuntu.com/usn/USN-1717-1
- https://blogs.oracle.com/sunsecurity/entry/cve_2013_0255_array_index
- https://bugzilla.redhat.com/show_bug.cgi?id=907892
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81917
- http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098586.html
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00059.html
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00060.html
- http://osvdb.org/89935
- http://rhn.redhat.com/errata/RHSA-2013-1475.html
- http://secunia.com/advisories/51923Vendor Advisory
- http://secunia.com/advisories/52819
- http://securitytracker.com/id?1028092
- http://www.debian.org/security/2013/dsa-2630
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.