CVE-2014-0063
31.03.2014, 14:58
Multiple stack-based buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via vectors related to an incorrect MAXDATELEN constant and datetime values involving (1) intervals, (2) timestamps, or (3) timezones, a different vulnerability than CVE-2014-0065.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| postgresql | postgresql | 𝑥 ≤ 8.4.19 |
| postgresql | postgresql | 8.4.1 |
| postgresql | postgresql | 8.4.2 |
| postgresql | postgresql | 8.4.3 |
| postgresql | postgresql | 8.4.4 |
| postgresql | postgresql | 8.4.5 |
| postgresql | postgresql | 8.4.6 |
| postgresql | postgresql | 8.4.7 |
| postgresql | postgresql | 8.4.8 |
| postgresql | postgresql | 8.4.9 |
| postgresql | postgresql | 8.4.10 |
| postgresql | postgresql | 8.4.11 |
| postgresql | postgresql | 8.4.12 |
| postgresql | postgresql | 8.4.13 |
| postgresql | postgresql | 8.4.14 |
| postgresql | postgresql | 8.4.15 |
| postgresql | postgresql | 8.4.16 |
| postgresql | postgresql | 8.4.17 |
| postgresql | postgresql | 8.4.18 |
| postgresql | postgresql | 9.0 |
| postgresql | postgresql | 9.0.1 |
| postgresql | postgresql | 9.0.2 |
| postgresql | postgresql | 9.0.3 |
| postgresql | postgresql | 9.0.4 |
| postgresql | postgresql | 9.0.5 |
| postgresql | postgresql | 9.0.6 |
| postgresql | postgresql | 9.0.7 |
| postgresql | postgresql | 9.0.8 |
| postgresql | postgresql | 9.0.9 |
| postgresql | postgresql | 9.0.10 |
| postgresql | postgresql | 9.0.11 |
| postgresql | postgresql | 9.0.12 |
| postgresql | postgresql | 9.0.13 |
| postgresql | postgresql | 9.0.14 |
| postgresql | postgresql | 9.0.15 |
| postgresql | postgresql | 9.1 |
| postgresql | postgresql | 9.1.1 |
| postgresql | postgresql | 9.1.2 |
| postgresql | postgresql | 9.1.3 |
| postgresql | postgresql | 9.1.4 |
| postgresql | postgresql | 9.1.5 |
| postgresql | postgresql | 9.1.6 |
| postgresql | postgresql | 9.1.7 |
| postgresql | postgresql | 9.1.8 |
| postgresql | postgresql | 9.1.9 |
| postgresql | postgresql | 9.1.10 |
| postgresql | postgresql | 9.1.11 |
| postgresql | postgresql | 9.2 |
| postgresql | postgresql | 9.2.1 |
| postgresql | postgresql | 9.2.2 |
| postgresql | postgresql | 9.2.3 |
| postgresql | postgresql | 9.2.4 |
| postgresql | postgresql | 9.2.5 |
| postgresql | postgresql | 9.2.6 |
| postgresql | postgresql | 9.3 |
| postgresql | postgresql | 9.3.1 |
| postgresql | postgresql | 9.3.2 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| postgresql-8.4 |
| ||||||||||||
| postgresql-9.1 |
| ||||||||||||
| postgresql-9.3 |
|
openSUSE / SLES Releases
openSUSE Product | |||||
|---|---|---|---|---|---|
| libecpg6 |
| ||||
| libpq5 |
| ||||
| libpq5-32bit |
| ||||
| postgresql10 |
| ||||
| postgresql10-contrib |
| ||||
| postgresql10-docs |
| ||||
| postgresql10-plperl |
| ||||
| postgresql10-plpython |
| ||||
| postgresql10-pltcl |
| ||||
| postgresql10-server |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| postgresql |
| ||
| postgresql-contrib |
| ||
| postgresql-devel |
| ||
| postgresql-docs |
| ||
| postgresql-libs |
| ||
| postgresql-plperl |
| ||
| postgresql-plpython |
| ||
| postgresql-pltcl |
| ||
| postgresql-server |
| ||
| postgresql-test |
|
Common Weakness Enumeration
References