CVE-2015-3165
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the…
Does this matter?
Lower severity and a low EPSS score (8.51%). Track it; it rarely justifies an emergency change on its own.
Description
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 8.51% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- canonical/ubuntu linux · debian/debian linux · apple/mac os x server · postgresql/postgresql
- Source
- secalert@redhat.com
References
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1194.html
- http://rhn.redhat.com/errata/RHSA-2015-1195.html
- http://rhn.redhat.com/errata/RHSA-2015-1196.html
- http://www.debian.org/security/2015/dsa-3269Third Party Advisory
- http://www.debian.org/security/2015/dsa-3270Third Party Advisory
- http://www.postgresql.org/about/news/1587/Vendor Advisory
- http://www.postgresql.org/docs/9.0/static/release-9-0-20.htmlRelease Notes
- http://www.postgresql.org/docs/9.1/static/release-9-1-16.htmlRelease Notes
- http://www.postgresql.org/docs/9.2/static/release-9-2-11.htmlRelease Notes
- http://www.postgresql.org/docs/9.3/static/release-9-3-7.htmlRelease Notes
- http://www.postgresql.org/docs/9.4/static/release-9-4-2.htmlRelease Notes
- http://www.securityfocus.com/bid/74787Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2621-1Vendor Advisory
- https://security.gentoo.org/glsa/201507-20
- https://support.apple.com/HT205219Third Party Advisory
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1194.html
- http://rhn.redhat.com/errata/RHSA-2015-1195.html
- http://rhn.redhat.com/errata/RHSA-2015-1196.html
- http://www.debian.org/security/2015/dsa-3269Third Party Advisory
- http://www.debian.org/security/2015/dsa-3270Third Party Advisory
- http://www.postgresql.org/about/news/1587/Vendor Advisory
- http://www.postgresql.org/docs/9.0/static/release-9-0-20.htmlRelease Notes
- http://www.postgresql.org/docs/9.1/static/release-9-1-16.htmlRelease Notes
- http://www.postgresql.org/docs/9.2/static/release-9-2-11.htmlRelease Notes
- http://www.postgresql.org/docs/9.3/static/release-9-3-7.htmlRelease Notes
- http://www.postgresql.org/docs/9.4/static/release-9-4-2.htmlRelease Notes
- http://www.securityfocus.com/bid/74787Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2621-1Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.