CVE-2015-3167
published 2019-11-20CVE-2015-3167: contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
4.13%
89.7th percentile
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_server_v5.0.3 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| postgresql | postgresql | < 9.0.20 | 9.0.20 |
| postgresql | postgresql | >= 9.1 < 9.1.16 | 9.1.16 |
| postgresql | postgresql | >= 9.2 < 9.2.11 | 9.2.11 |
| postgresql | postgresql | >= 9.3 < 9.3.7 | 9.3.7 |
| postgresql | postgresql | >= 9.4 < 9.4.2 | 9.4.2 |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
| postgresql_global_development_group | postgresql | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2015-05-25·CVSS 4.3
CVE-2015-3165 [MEDIUM] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: Several security issues were fixed in PostgreSQL.
Benkocs Norbert Attila discovered that PostgreSQL incorrectly handled
authentication timeouts. A remote attacker could use this flaw to cause the
unauthenticated session to crash, possibly leading to a security issue.
(CVE-2015-3165)
Noah Misch discovered that PostgreSQL incorrectly handled certain standard
library function return values, possibly leading to security issues.
(CVE-2015-3166)
Noah Misch discovered that the pgcrypto function could return different
error messages when decrypting using an incorrect key, possibly leading to
a security issue. (CVE-2015-3167)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system updat
Red Hat
postgresql: pgcrypto has multiple error messages for decryption with an incorrect key.
vendor_redhat·2015-05-22·CVSS 7.5
CVE-2015-3167 [HIGH] CWE-209 postgresql: pgcrypto has multiple error messages for decryption with an incorrect key.
postgresql: pgcrypto has multiple error messages for decryption with an incorrect key.
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
It was discovered that the pgcrypto module could return different error messages when decrypting certain data with an incorrect key. This could potentially help an authenticated user to launch a possible cryptographic attack, although no suitable attack is currently known.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This flaw has been rated as having Low security impac
Apple
CVE-2015-3167: OS X Server v5.0.3
vendor_apple·CVSS 7.5
CVE-2015-3167 [HIGH] CVE-2015-3167: OS X Server v5.0.3
Apple Security Update: About the security content of OS X Server v5.0.3
Product: OS X Server v5.0.3
CVE: CVE-2015-3167
Component: CVE-2015-3167
GHSA
GHSA-xj65-3378-xxg3: contrib/pgcrypto in PostgreSQL before 9
ghsa_unreviewed·2022-05-24
CVE-2015-3167 [HIGH] CWE-200 GHSA-xj65-3378-xxg3: contrib/pgcrypto in PostgreSQL before 9
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
OSV
postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
osv·2015-05-25·CVSS 4.3
CVE-2015-3165 [MEDIUM] postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
Benkocs Norbert Attila discovered that PostgreSQL incorrectly handled
authentication timeouts. A remote attacker could use this flaw to cause the
unauthenticated session to crash, possibly leading to a security issue.
(CVE-2015-3165)
Noah Misch discovered that PostgreSQL incorrectly handled certain standard
library function return values, possibly leading to security issues.
(CVE-2015-3166)
Noah Misch discovered that the pgcrypto function could return different
error messages when decrypting using an incorrect key, possibly leading to
a security issue. (CVE-2015-3167)
OSV
CVE-2015-3167: contrib/pgcrypto in PostgreSQL before 9
osv·2015-05-22·CVSS 7.5
CVE-2015-3167 [HIGH] CVE-2015-3167: contrib/pgcrypto in PostgreSQL before 9
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
No detection rules found.
No public exploits indexed.
http://ubuntu.com/usn/usn-2621-1http://www.debian.org/security/2015/dsa-3269http://www.debian.org/security/2015/dsa-3270http://www.postgresql.org/about/news/1587/http://www.postgresql.org/docs/9.0/static/release-9-0-20.htmlhttp://www.postgresql.org/docs/9.1/static/release-9-1-16.htmlhttp://www.postgresql.org/docs/9.2/static/release-9-2-11.htmlhttp://www.postgresql.org/docs/9.3/static/release-9-3-7.htmlhttp://www.postgresql.org/docs/9.4/static/release-9-4-2.htmlhttp://ubuntu.com/usn/usn-2621-1http://www.debian.org/security/2015/dsa-3269http://www.debian.org/security/2015/dsa-3270http://www.postgresql.org/about/news/1587/http://www.postgresql.org/docs/9.0/static/release-9-0-20.htmlhttp://www.postgresql.org/docs/9.1/static/release-9-1-16.htmlhttp://www.postgresql.org/docs/9.2/static/release-9-2-11.htmlhttp://www.postgresql.org/docs/9.3/static/release-9-3-7.htmlhttp://www.postgresql.org/docs/9.4/static/release-9-4-2.html
2019-11-20
Published