CVE-2014-8161
published 2020-01-27CVE-2014-8161: PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain…
PriorityP420medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
2.51%
83.0th percentile
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_server_v5.0.3 | — | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| postgresql | postgresql | < 9.0.19 | 9.0.19 |
| postgresql | postgresql | >= 9.1.0 < 9.1.15 | 9.1.15 |
| postgresql | postgresql | >= 9.2.0 < 9.2.10 | 9.2.10 |
| postgresql | postgresql | >= 9.3.0 < 9.3.6 | 9.3.6 |
| postgresql | postgresql | >= 9.4.0 < 9.4.1 | 9.4.1 |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2015-02-11·CVSS 4.3
CVE-2014-8161 [MEDIUM] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: Several security issues were fixed in PostgreSQL.
Stephen Frost discovered that PostgreSQL incorrectly displayed certain
values in error messages. An authenticated user could gain access to seeing
certain values, contrary to expected permissions. (CVE-2014-8161)
Andres Freund, Peter Geoghegan and Noah Misch discovered that PostgreSQL
incorrectly handled buffers in to_char functions. An authenticated attacker
could possibly use this issue to cause PostgreSQL to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2015-0241)
It was discovered that PostgreSQL incorrectly handled memory in the
pgcrypto extension. An authenticated attacker could possibly use this issue
to cause PostgreSQL to crash, resulting in a denial
Red Hat
postgresql: information leak through constraint violation errors
vendor_redhat·2015-02-05·CVSS 4.3
CVE-2014-8161 [MEDIUM] CWE-662 postgresql: information leak through constraint violation errors
postgresql: information leak through constraint violation errors
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
An information leak flaw was found in the wathe PostgreSQL database server handled certain error messages. An authenticated database user could possibly obtain the results of a query they did not have privileges to execute by observing the constraint violation error messages produced when the query was executed.
Package: postgresql (CloudForms Management Engine 5) - Will not fix
Package: postgresql92-postgresql (CloudForms Management Engine 5) - Will not fix
Package: postgres
Apple
CVE-2014-8161: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 4.3
CVE-2014-8161 [MEDIUM] CVE-2014-8161: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2014-8161
Component: CVE-2014-8161
Apple
CVE-2014-8161: OS X Server v5.0.3
vendor_apple·CVSS 4.3
CVE-2014-8161 [MEDIUM] CVE-2014-8161: OS X Server v5.0.3
Apple Security Update: About the security content of OS X Server v5.0.3
Product: OS X Server v5.0.3
CVE: CVE-2014-8161
Component: CVE-2014-8161
GHSA
GHSA-qxj3-8772-4f6w: PostgreSQL before 9
ghsa_unreviewed·2022-05-17
CVE-2014-8161 [MEDIUM] CWE-209 GHSA-qxj3-8772-4f6w: PostgreSQL before 9
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
OSV
postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
osv·2015-02-11·CVSS 4.3
CVE-2014-8161 [MEDIUM] postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
Stephen Frost discovered that PostgreSQL incorrectly displayed certain
values in error messages. An authenticated user could gain access to seeing
certain values, contrary to expected permissions. (CVE-2014-8161)
Andres Freund, Peter Geoghegan and Noah Misch discovered that PostgreSQL
incorrectly handled buffers in to_char functions. An authenticated attacker
could possibly use this issue to cause PostgreSQL to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2015-0241)
It was discovered that PostgreSQL incorrectly handled memory in the
pgcrypto extension. An authenticated attacker could possibly use this issue
to cause PostgreSQL to crash, resulting in a denial of service, or
OSV
CVE-2014-8161: PostgreSQL before 9
osv·2015-02-06·CVSS 4.3
CVE-2014-8161 [MEDIUM] CVE-2014-8161: PostgreSQL before 9
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
No detection rules found.
No public exploits indexed.
http://www.debian.org/security/2015/dsa-3155http://www.postgresql.org/about/news/1569/http://www.postgresql.org/docs/9.4/static/release-9-4-1.htmlhttp://www.postgresql.org/docs/current/static/release-9-0-19.htmlhttp://www.postgresql.org/docs/current/static/release-9-1-15.htmlhttp://www.postgresql.org/docs/current/static/release-9-2-10.htmlhttp://www.postgresql.org/docs/current/static/release-9-3-6.htmlhttp://www.debian.org/security/2015/dsa-3155http://www.postgresql.org/about/news/1569/http://www.postgresql.org/docs/9.4/static/release-9-4-1.htmlhttp://www.postgresql.org/docs/current/static/release-9-0-19.htmlhttp://www.postgresql.org/docs/current/static/release-9-1-15.htmlhttp://www.postgresql.org/docs/current/static/release-9-2-10.htmlhttp://www.postgresql.org/docs/current/static/release-9-3-6.html
2020-01-27
Published