CVE-2015-0244
published 2020-01-27CVE-2015-0244: PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.36%
90.2th percentile
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_server_v5.0.3 | — | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| postgresql | postgresql | < 9.0.19 | 9.0.19 |
| postgresql | postgresql | >= 9.1.0 < 9.1.15 | 9.1.15 |
| postgresql | postgresql | >= 9.2.0 < 9.2.10 | 9.2.10 |
| postgresql | postgresql | >= 9.3.0 < 9.3.6 | 9.3.6 |
| postgresql | postgresql | >= 9.4.0 < 9.4.1 | 9.4.1 |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
postgresql: loss of frontend/backend protocol synchronization after an error
vendor_redhat·2015-02-16·CVSS 9.8
CVE-2015-0244 [CRITICAL] CWE-662 postgresql: loss of frontend/backend protocol synchronization after an error
postgresql: loss of frontend/backend protocol synchronization after an error
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.
A flaw was found in the way PostgreSQL handled certain errors that were generated during protocol synchronization. An authenticated database user could use this flaw to inject queries into an existing connection.
Package: postgresql (CloudForms Manage
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2015-02-11·CVSS 4.3
CVE-2014-8161 [MEDIUM] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: Several security issues were fixed in PostgreSQL.
Stephen Frost discovered that PostgreSQL incorrectly displayed certain
values in error messages. An authenticated user could gain access to seeing
certain values, contrary to expected permissions. (CVE-2014-8161)
Andres Freund, Peter Geoghegan and Noah Misch discovered that PostgreSQL
incorrectly handled buffers in to_char functions. An authenticated attacker
could possibly use this issue to cause PostgreSQL to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2015-0241)
It was discovered that PostgreSQL incorrectly handled memory in the
pgcrypto extension. An authenticated attacker could possibly use this issue
to cause PostgreSQL to crash, resulting in a denial
Apple
CVE-2015-0244: OS X Server v5.0.3
vendor_apple·CVSS 9.8
CVE-2015-0244 [CRITICAL] CVE-2015-0244: OS X Server v5.0.3
Apple Security Update: About the security content of OS X Server v5.0.3
Product: OS X Server v5.0.3
CVE: CVE-2015-0244
Component: CVE-2015-0244
Apple
CVE-2015-0244: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 9.8
CVE-2015-0244 [CRITICAL] CVE-2015-0244: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2015-0244
Component: CVE-2015-0244
Impact: Multiple vulnerabilities existed in Python 2.7.6, the most serious of which may lead to arbitrary code execution
Description: Multiple vulnerabilities existed in Python versions prior to 2.7.6. These were addressed by updating Python to version 2.7.10.
GHSA
GHSA-xvhg-pwg9-qp4r: PostgreSQL before 9
ghsa_unreviewed·2022-05-24
CVE-2015-0244 [CRITICAL] CWE-89 GHSA-xvhg-pwg9-qp4r: PostgreSQL before 9
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.
OSV
postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
osv·2015-02-11·CVSS 4.3
CVE-2014-8161 [MEDIUM] postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
Stephen Frost discovered that PostgreSQL incorrectly displayed certain
values in error messages. An authenticated user could gain access to seeing
certain values, contrary to expected permissions. (CVE-2014-8161)
Andres Freund, Peter Geoghegan and Noah Misch discovered that PostgreSQL
incorrectly handled buffers in to_char functions. An authenticated attacker
could possibly use this issue to cause PostgreSQL to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2015-0241)
It was discovered that PostgreSQL incorrectly handled memory in the
pgcrypto extension. An authenticated attacker could possibly use this issue
to cause PostgreSQL to crash, resulting in a denial of service, or
OSV
CVE-2015-0244: PostgreSQL before 9
osv·2015-02-06·CVSS 9.8
CVE-2015-0244 [CRITICAL] CVE-2015-0244: PostgreSQL before 9
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.
No detection rules found.
No public exploits indexed.
http://www.debian.org/security/2015/dsa-3155http://www.postgresql.org/about/news/1569/http://www.postgresql.org/docs/9.4/static/release-9-4-1.htmlhttp://www.postgresql.org/docs/current/static/release-9-0-19.htmlhttp://www.postgresql.org/docs/current/static/release-9-1-15.htmlhttp://www.postgresql.org/docs/current/static/release-9-2-10.htmlhttp://www.postgresql.org/docs/current/static/release-9-3-6.htmlhttp://www.debian.org/security/2015/dsa-3155http://www.postgresql.org/about/news/1569/http://www.postgresql.org/docs/9.4/static/release-9-4-1.htmlhttp://www.postgresql.org/docs/current/static/release-9-0-19.htmlhttp://www.postgresql.org/docs/current/static/release-9-1-15.htmlhttp://www.postgresql.org/docs/current/static/release-9-2-10.htmlhttp://www.postgresql.org/docs/current/static/release-9-3-6.html
2020-01-27
Published