CVE-2016-5423

PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL pointer dereference and server crash), obtain sensitive memory information, or possibly execute arbitrary code via (1) a CASE expression within the test value subexpression of another CASE or (2) inlining of an SQL function that implements the equality operator used for a CASE expression involving values of different types.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.3 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
debiandebian_linux
8.0
postgresqlpostgresql
𝑥
≤ 9.1.22
postgresqlpostgresql
9.2
postgresqlpostgresql
9.2.1
postgresqlpostgresql
9.2.2
postgresqlpostgresql
9.2.3
postgresqlpostgresql
9.2.4
postgresqlpostgresql
9.2.5
postgresqlpostgresql
9.2.6
postgresqlpostgresql
9.2.7
postgresqlpostgresql
9.2.8
postgresqlpostgresql
9.2.9
postgresqlpostgresql
9.2.10
postgresqlpostgresql
9.2.11
postgresqlpostgresql
9.2.12
postgresqlpostgresql
9.2.13
postgresqlpostgresql
9.2.14
postgresqlpostgresql
9.2.15
postgresqlpostgresql
9.2.16
postgresqlpostgresql
9.2.17
postgresqlpostgresql
9.3
postgresqlpostgresql
9.3.1
postgresqlpostgresql
9.3.2
postgresqlpostgresql
9.3.3
postgresqlpostgresql
9.3.4
postgresqlpostgresql
9.3.5
postgresqlpostgresql
9.3.6
postgresqlpostgresql
9.3.7
postgresqlpostgresql
9.3.8
postgresqlpostgresql
9.3.9
postgresqlpostgresql
9.3.10
postgresqlpostgresql
9.3.11
postgresqlpostgresql
9.3.12
postgresqlpostgresql
9.3.13
postgresqlpostgresql
9.4
postgresqlpostgresql
9.4.1
postgresqlpostgresql
9.4.2
postgresqlpostgresql
9.4.3
postgresqlpostgresql
9.4.4
postgresqlpostgresql
9.4.5
postgresqlpostgresql
9.4.6
postgresqlpostgresql
9.4.7
postgresqlpostgresql
9.4.8
postgresqlpostgresql
9.5
postgresqlpostgresql
9.5.1
postgresqlpostgresql
9.5.2
postgresqlpostgresql
9.5.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-8.4
zesty
dne
yakkety
dne
xenial
dne
trusty
dne
precise
ignored
postgresql-9.1
zesty
dne
yakkety
dne
xenial
dne
trusty
Fixed 9.1.23-0ubuntu0.14.04
released
precise
Fixed 9.1.23-0ubuntu0.12.04
released
postgresql-9.3
zesty
dne
yakkety
dne
xenial
dne
trusty
Fixed 9.3.14-0ubuntu0.14.04
released
precise
dne
postgresql-9.5
zesty
dne
yakkety
not-affected
xenial
Fixed 9.5.4-0ubuntu0.16.04
released
trusty
dne
precise
dne
References