CVE-2015-0244

EUVD-2015-0266
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
Affected Products (NVD)
VendorProductVersion
postgresqlpostgresql
𝑥
< 9.0.19
postgresqlpostgresql
9.1.0 ≤
𝑥
< 9.1.15
postgresqlpostgresql
9.2.0 ≤
𝑥
< 9.2.10
postgresqlpostgresql
9.3.0 ≤
𝑥
< 9.3.6
postgresqlpostgresql
9.4.0 ≤
𝑥
< 9.4.1
debiandebian_linux
7.0
debiandebian_linux
8.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-8.4
lucid
Fixed 8.4.22-0ubuntu0.10.04.1
released
precise
ignored
trusty
dne
utopic
dne
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne
postgresql-9.1
lucid
dne
precise
Fixed 9.1.15-0ubuntu0.12.04
released
trusty
Fixed 9.1.15-0ubuntu0.14.04
released
utopic
dne
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne
postgresql-9.3
lucid
dne
precise
dne
trusty
Fixed 9.3.6-0ubuntu0.14.04
released
utopic
dne
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne
postgresql-9.4
lucid
dne
precise
dne
trusty
dne
utopic
Fixed 9.4.1-0ubuntu0.14.10
released
vivid
not-affected
wily
not-affected
xenial
dne
yakkety
dne
zesty
dne