Description
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-152-1 | postgresql-8.4 update |
Debian DSA |
DSA-3155-1 | postgresql-9.1 security update |
EUVD |
EUVD-2015-0266 | PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation. |
Ubuntu USN |
USN-2499-1 | PostgreSQL vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T04:03:10.495Z
Reserved: 2014-11-18T00:00:00.000Z
Link: CVE-2015-0244
No data.
Status : Modified
Published: 2020-01-27T16:15:10.843
Modified: 2024-11-21T02:22:38.417
Link: CVE-2015-0244
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN