CVE-2014-2669
Multiple integer overflows in contrib/hstore/hstore_io.c in PostgreSQL 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact via vectors related to the (1)…
Does this matter?
Lower severity and a low EPSS score (3.44%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple integer overflows in contrib/hstore/hstore_io.c in PostgreSQL 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact via vectors related to the (1) hstore_recv, (2) hstore_from_arrays, and (3) hstore_from_array functions in contrib/hstore/hstore_io.c; and the (4) hstoreArrayToPairs function in contrib/hstore/hstore_op.c, which triggers a buffer overflow. NOTE: this issue was SPLIT from CVE-2014-0064 because it has a different set of affected versions.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 3.44% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- postgresql/postgresql
- Source
- cve@mitre.org
References
- http://rhn.redhat.com/errata/RHSA-2014-0221.html
- http://rhn.redhat.com/errata/RHSA-2014-0469.html
- http://wiki.postgresql.org/wiki/20140220securityreleaseVendor Advisory
- http://www.debian.org/security/2014/dsa-2864
- http://www.debian.org/security/2014/dsa-2865
- http://www.postgresql.org/about/news/1506/Vendor Advisory
- http://www.postgresql.org/support/security/
- https://github.com/postgres/postgres/commit/31400a673325147e1205326008e32135a78b4d8a
- http://rhn.redhat.com/errata/RHSA-2014-0221.html
- http://rhn.redhat.com/errata/RHSA-2014-0469.html
- http://wiki.postgresql.org/wiki/20140220securityreleaseVendor Advisory
- http://www.debian.org/security/2014/dsa-2864
- http://www.debian.org/security/2014/dsa-2865
- http://www.postgresql.org/about/news/1506/Vendor Advisory
- http://www.postgresql.org/support/security/
- https://github.com/postgres/postgres/commit/31400a673325147e1205326008e32135a78b4d8a
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.