CVE-2015-0243
published 2020-01-27CVE-2015-0243: Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1…
PriorityP350high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
5.12%
91.5th percentile
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_server_v5.0.3 | — | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| postgresql | postgresql | < 9.0.19 | 9.0.19 |
| postgresql | postgresql | >= 9.1.0 < 9.1.15 | 9.1.15 |
| postgresql | postgresql | >= 9.2.0 < 9.2.10 | 9.2.10 |
| postgresql | postgresql | >= 9.3.0 < 9.3.6 | 9.3.6 |
| postgresql | postgresql | >= 9.4.0 < 9.4.1 | 9.4.1 |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
postgresql: buffer overflow flaws in contrib/pgcrypto
vendor_redhat·2015-02-16·CVSS 8.8
CVE-2015-0243 [HIGH] CWE-122 postgresql: buffer overflow flaws in contrib/pgcrypto
postgresql: buffer overflow flaws in contrib/pgcrypto
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
A stack-buffer overflow flaw was found in PostgreSQL's pgcrypto module. An authenticated database user could use this flaw to cause PostgreSQL to crash or, potentially, execute arbitrary code with the permissions of the user running PostgreSQL.
Package: postgresql (CloudForms Management Engine 5) - Will not fix
Package: postgresql92-postgresql (CloudForms Management Engine 5) - Will not fix
Package: postgresql (Red Hat Enterprise Linux 5) - Will
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2015-02-11·CVSS 4.3
CVE-2014-8161 [MEDIUM] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: Several security issues were fixed in PostgreSQL.
Stephen Frost discovered that PostgreSQL incorrectly displayed certain
values in error messages. An authenticated user could gain access to seeing
certain values, contrary to expected permissions. (CVE-2014-8161)
Andres Freund, Peter Geoghegan and Noah Misch discovered that PostgreSQL
incorrectly handled buffers in to_char functions. An authenticated attacker
could possibly use this issue to cause PostgreSQL to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2015-0241)
It was discovered that PostgreSQL incorrectly handled memory in the
pgcrypto extension. An authenticated attacker could possibly use this issue
to cause PostgreSQL to crash, resulting in a denial
Apple
CVE-2015-0243: OS X Server v5.0.3
vendor_apple·CVSS 8.8
CVE-2015-0243 [HIGH] CVE-2015-0243: OS X Server v5.0.3
Apple Security Update: About the security content of OS X Server v5.0.3
Product: OS X Server v5.0.3
CVE: CVE-2015-0243
Component: CVE-2015-0243
Apple
CVE-2015-0243: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 8.8
CVE-2015-0243 [HIGH] CVE-2015-0243: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2015-0243
Component: CVE-2015-0243
GHSA
GHSA-4c7q-44j3-76m6: Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9
ghsa_unreviewed·2022-05-24
CVE-2015-0243 [MEDIUM] GHSA-4c7q-44j3-76m6: Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
OSV
postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
osv·2015-02-11·CVSS 4.3
CVE-2014-8161 [MEDIUM] postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
Stephen Frost discovered that PostgreSQL incorrectly displayed certain
values in error messages. An authenticated user could gain access to seeing
certain values, contrary to expected permissions. (CVE-2014-8161)
Andres Freund, Peter Geoghegan and Noah Misch discovered that PostgreSQL
incorrectly handled buffers in to_char functions. An authenticated attacker
could possibly use this issue to cause PostgreSQL to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2015-0241)
It was discovered that PostgreSQL incorrectly handled memory in the
pgcrypto extension. An authenticated attacker could possibly use this issue
to cause PostgreSQL to crash, resulting in a denial of service, or
OSV
CVE-2015-0243: Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9
osv·2015-02-06·CVSS 8.8
CVE-2015-0243 [HIGH] CVE-2015-0243: Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
No detection rules found.
No public exploits indexed.
arXiv
The Semantic Trap: Do Fine-tuned LLMs Learn Vulnerability Root Cause or Just Functional Pattern?
arxiv_fulltext·2026-02-02
The Semantic Trap: Do Fine-tuned LLMs Learn Vulnerability Root Cause or Just Functional Pattern?
The Semantic Trap: Do Fine-tuned LLMs Learn Vulnerability Root Cause or Just Functional Pattern?
Feiyang Huang
[email protected]
College of Computer Science and Technology, Zhejiang University
Hangzhou
China
Yuqiang Sun
[email protected]
0000-0003-4340-3371
Nanyang Technological University
Singapore
Singapore
Fan Zhang
[email protected]
[1]
College of Computer Science and Technology, Zhejiang University
Hangzhou
China
Ziqi Yang
[email protected]
College of Computer Science and Technology, Zhejiang University
Hangzhou
China
Han Liu
[email protected]
0009-0000-8384-7933
College of Cryptology and Cyber Science, Nankai University
Tianjin
China
Yang Liu
[email protected]
0000-0001-7300-9215
Nanyang Technological University
Singapore
Singapore
Huang et al.
## Abstract
L
Bugzilla
CVE-2015-0243 postgresql: buffer overflow flaws in contrib/pgcrypto
bugzilla·2015-02-03·CVSS 8.8
CVE-2015-0243 [HIGH] CVE-2015-0243 postgresql: buffer overflow flaws in contrib/pgcrypto
CVE-2015-0243 postgresql: buffer overflow flaws in contrib/pgcrypto
The PostgreSQL project reports the following issue:
Errors in memory size tracking within the pgcrypto module permitted stack buffer overruns and improper dependence on the contents of uninitialized memory. The buffer overrun cases can crash the server, and we have not ruled out the possibility of attacks that lead to privilege escalation.
Acknowledgements:
Red Hat would like to thank the PostgreSQL project for reporting this issue. Upstream acknowledges Marko Tiikkaja as the original reporter.
Discussion:
External References:
http://www.postgresql.org/about/news/1569/
---
Upstream commit:
https://github.com/postgres/postgres/commit/1dc75515868454c645ded22d38054ec693e23ec6
---
This issue was addressed in Fedora
http://www.debian.org/security/2015/dsa-3155http://www.postgresql.org/about/news/1569/http://www.postgresql.org/docs/9.4/static/release-9-4-1.htmlhttp://www.postgresql.org/docs/current/static/release-9-0-19.htmlhttp://www.postgresql.org/docs/current/static/release-9-1-15.htmlhttp://www.postgresql.org/docs/current/static/release-9-2-10.htmlhttp://www.postgresql.org/docs/current/static/release-9-3-6.htmlhttp://www.debian.org/security/2015/dsa-3155http://www.postgresql.org/about/news/1569/http://www.postgresql.org/docs/9.4/static/release-9-4-1.htmlhttp://www.postgresql.org/docs/current/static/release-9-0-19.htmlhttp://www.postgresql.org/docs/current/static/release-9-1-15.htmlhttp://www.postgresql.org/docs/current/static/release-9-2-10.htmlhttp://www.postgresql.org/docs/current/static/release-9-3-6.html
2020-01-27
Published