CVE-2015-3166

The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via unknown vectors, as demonstrated by an out-of-memory error.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
postgresqlpostgresql
𝑥
< 9.0.20
postgresqlpostgresql
9.1 ≤
𝑥
< 9.1.16
postgresqlpostgresql
9.2 ≤
𝑥
< 9.2.11
postgresqlpostgresql
9.3 ≤
𝑥
< 9.3.7
postgresqlpostgresql
9.4 ≤
𝑥
< 9.4.2
debiandebian_linux
7.0
debiandebian_linux
8.0
debiandebian_linux
9.0
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
14.10
canonicalubuntu_linux
15.04
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-8.4
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
precise
ignored
postgresql-9.1
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
Fixed 9.1.16-0ubuntu0.14.04
released
precise
Fixed 9.1.16-0ubuntu0.12.04
released
postgresql-9.3
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
Fixed 9.3.7-0ubuntu0.14.04
released
precise
dne
postgresql-9.4
zesty
dne
yakkety
dne
xenial
dne
wily
Fixed 9.4.2-1
released
vivid
Fixed 9.4.2-0ubuntu0.15.04
released
utopic
Fixed 9.4.2-0ubuntu0.14.10
released
trusty
dne
precise
dne