CVE-2015-3165
published 2015-05-28CVE-2015-3165: Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote…
PriorityP426medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
8.57%
94.5th percentile
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x_server | — | — |
| apple | os_x_server_v5.0.3 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| postgresql | postgresql | <= 9.0.19 | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2015-05-25·CVSS 4.3
CVE-2015-3165 [MEDIUM] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: Several security issues were fixed in PostgreSQL.
Benkocs Norbert Attila discovered that PostgreSQL incorrectly handled
authentication timeouts. A remote attacker could use this flaw to cause the
unauthenticated session to crash, possibly leading to a security issue.
(CVE-2015-3165)
Noah Misch discovered that PostgreSQL incorrectly handled certain standard
library function return values, possibly leading to security issues.
(CVE-2015-3166)
Noah Misch discovered that the pgcrypto function could return different
error messages when decrypting using an incorrect key, possibly leading to
a security issue. (CVE-2015-3167)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system updat
Red Hat
postgresql: double-free after authentication timeout
vendor_redhat·2015-05-22·CVSS 4.3
CVE-2015-3165 [MEDIUM] CWE-416 postgresql: double-free after authentication timeout
postgresql: double-free after authentication timeout
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.
A double-free flaw was found in the way PostgreSQL handled connections. An unauthenticated attacker could possibly exploit this flaw to crash the PostgreSQL backend by disconnecting at approximately the same time as the authentication time out was triggered.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This flaw has been rated as having Moderate security imp
Apple
CVE-2015-3165: OS X Server v5.0.3
vendor_apple·CVSS 4.3
CVE-2015-3165 [MEDIUM] CVE-2015-3165: OS X Server v5.0.3
Apple Security Update: About the security content of OS X Server v5.0.3
Product: OS X Server v5.0.3
CVE: CVE-2015-3165
Component: CVE-2015-3165
GHSA
GHSA-qw8w-35hc-552q: Double free vulnerability in PostgreSQL before 9
ghsa_unreviewed·2022-05-14
CVE-2015-3165 [MEDIUM] GHSA-qw8w-35hc-552q: Double free vulnerability in PostgreSQL before 9
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.
OSV
postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
osv·2015-05-25·CVSS 4.3
CVE-2015-3165 [MEDIUM] postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
Benkocs Norbert Attila discovered that PostgreSQL incorrectly handled
authentication timeouts. A remote attacker could use this flaw to cause the
unauthenticated session to crash, possibly leading to a security issue.
(CVE-2015-3165)
Noah Misch discovered that PostgreSQL incorrectly handled certain standard
library function return values, possibly leading to security issues.
(CVE-2015-3166)
Noah Misch discovered that the pgcrypto function could return different
error messages when decrypting using an incorrect key, possibly leading to
a security issue. (CVE-2015-3167)
OSV
CVE-2015-3165: Double free vulnerability in PostgreSQL before 9
osv·2015-05-22·CVSS 4.3
CVE-2015-3165 [MEDIUM] CVE-2015-3165: Double free vulnerability in PostgreSQL before 9
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1194.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1195.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1196.htmlhttp://www.debian.org/security/2015/dsa-3269http://www.debian.org/security/2015/dsa-3270http://www.postgresql.org/about/news/1587/http://www.postgresql.org/docs/9.0/static/release-9-0-20.htmlhttp://www.postgresql.org/docs/9.1/static/release-9-1-16.htmlhttp://www.postgresql.org/docs/9.2/static/release-9-2-11.htmlhttp://www.postgresql.org/docs/9.3/static/release-9-3-7.htmlhttp://www.postgresql.org/docs/9.4/static/release-9-4-2.htmlhttp://www.securityfocus.com/bid/74787http://www.ubuntu.com/usn/USN-2621-1https://security.gentoo.org/glsa/201507-20https://support.apple.com/HT205219http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1194.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1195.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1196.htmlhttp://www.debian.org/security/2015/dsa-3269http://www.debian.org/security/2015/dsa-3270http://www.postgresql.org/about/news/1587/http://www.postgresql.org/docs/9.0/static/release-9-0-20.htmlhttp://www.postgresql.org/docs/9.1/static/release-9-1-16.htmlhttp://www.postgresql.org/docs/9.2/static/release-9-2-11.htmlhttp://www.postgresql.org/docs/9.3/static/release-9-3-7.htmlhttp://www.postgresql.org/docs/9.4/static/release-9-4-2.htmlhttp://www.securityfocus.com/bid/74787http://www.ubuntu.com/usn/USN-2621-1https://security.gentoo.org/glsa/201507-20https://support.apple.com/HT205219
2015-05-28
Published