CVE-2016-3065
11.04.2016, 15:59
The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attackers to bypass intended access restrictions and consequently obtain sensitive server memory information or cause a denial of service (server crash) via a crafted bytea value in a BRIN index page.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| postgresql | postgresql | 9.5 |
| postgresql | postgresql | 9.5.1 |
𝑥
= Vulnerable software versions
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||
|---|---|---|---|---|---|---|---|
| libecpg6 |
| ||||||
| libpq5 |
| ||||||
| libpq5-32bit |
| ||||||
| postgresql10 |
| ||||||
| postgresql10-contrib |
| ||||||
| postgresql10-docs |
| ||||||
| postgresql10-plperl |
| ||||||
| postgresql10-plpython |
| ||||||
| postgresql10-pltcl |
| ||||||
| postgresql10-server |
| ||||||
| postgresql96 |
| ||||||
| postgresql96-contrib |
| ||||||
| postgresql96-docs |
| ||||||
| postgresql96-server |
|
Common Weakness Enumeration
References