CVE-2015-5289
published 2015-10-26CVE-2015-5289: Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of…
PriorityP333medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
5.04%
91.3th percentile
Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| postgresql | postgresql | >= 9.3.0 < 9.3.10 | 9.3.10 |
| postgresql | postgresql | >= 9.4.0 < 9.4.5 | 9.4.5 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv6.4MEDIUM
vendor_redhat6.4MEDIUM
vendor_ubuntu6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2015-10-16·CVSS 6.4
CVE-2015-5288 [MEDIUM] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: PostgreSQL could be made to crash or expose private information if it
handled specially crafted data.
Josh Kupershmidt discovered the pgCrypto extension could expose
several bytes of server memory if the crypt() function was provided a
too-short salt. An attacker could use this flaw to read private data.
(CVE-2015-5288)
Oskari Saarenmaa discovered that the json and jsonb handlers could exhaust
available stack space. An attacker could use this flaw to perform a denial
of service attack. This issue only affected Ubuntu 14.04 LTS and Ubuntu
15.04. (CVE-2015-5289)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart PostgreSQL to
make all the necessary change
Red Hat
postgresql: stack overflow DoS when parsing json or jsonb inputs
vendor_redhat·2015-10-08·CVSS 6.4
CVE-2015-5289 [MEDIUM] CWE-131 postgresql: stack overflow DoS when parsing json or jsonb inputs
postgresql: stack overflow DoS when parsing json or jsonb inputs
Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.
A stack overflow flaw was discovered in the way the PostgreSQL core server processed certain JSON or JSONB input. An authenticated attacker could possibly use this flaw to crash the server backend by sending specially crafted JSON or JSONB input.
Package: postgresql (Red Hat Enterprise Linux 5) - Not affected
Package: postgresql84 (Red Hat Enterprise Linux 5) - Not affected
Package: postgresql (Red Hat Enterprise Linux 6) - Not affected
Package: postgresql92
GHSA
GHSA-mp2m-64j4-6889: Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9
ghsa_unreviewed·2022-05-17
CVE-2015-5289 [MEDIUM] CWE-119 GHSA-mp2m-64j4-6889: Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9
Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.
OSV
postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
osv·2015-10-16·CVSS 6.4
CVE-2015-5288 [MEDIUM] postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
Josh Kupershmidt discovered the pgCrypto extension could expose
several bytes of server memory if the crypt() function was provided a
too-short salt. An attacker could use this flaw to read private data.
(CVE-2015-5288)
Oskari Saarenmaa discovered that the json and jsonb handlers could exhaust
available stack space. An attacker could use this flaw to perform a denial
of service attack. This issue only affected Ubuntu 14.04 LTS and Ubuntu
15.04. (CVE-2015-5289)
OSV
CVE-2015-5289: Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9
osv·2015-10-09·CVSS 6.4
CVE-2015-5289 [MEDIUM] CVE-2015-5289: Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9
Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5288 CVE-2015-5289 postgresql: various flaws [fedora-all]
bugzilla·2015-10-09·CVSS 6.4
CVE-2015-5288 [MEDIUM] CVE-2015-5288 CVE-2015-5289 postgresql: various flaws [fedora-all]
CVE-2015-5288 CVE-2015-5289 postgresql: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
Bugzilla
CVE-2015-5289 postgresql: stack overflow DoS when parsing json or jsonb inputs
bugzilla·2015-10-09·CVSS 6.4
CVE-2015-5289 [MEDIUM] CVE-2015-5289 postgresql: stack overflow DoS when parsing json or jsonb inputs
CVE-2015-5289 postgresql: stack overflow DoS when parsing json or jsonb inputs
A vulnerability in posgresql allowing an attacker to cause DoS. Json or jsonb input values constructed from arbitrary user input can crash the PostgreSQL server, terminating all active database connections and cause a denial of service.
Upstream patches:
http://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=08fa47c4850cea32c3116665975bca219fbf2fe6
http://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=30cb12881de55bc91a2cbde29d836bd3332612c3
http://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=5976097c0fce03f8cc201aefc4445ad57e09bb75
http://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=9e36c91b468d7d821b77214337ff891811b4b337
External reference:
http://www.postgresql.org/abo
Bugzilla
CVE-2015-5288 CVE-2015-5289 mingw-postgresql: various flaws [fedora-all]
bugzilla·2015-10-09·CVSS 6.4
CVE-2015-5288 [MEDIUM] CVE-2015-5288 CVE-2015-5289 mingw-postgresql: various flaws [fedora-all]
CVE-2015-5288 CVE-2015-5289 mingw-postgresql: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
http://git.postgresql.org/gitweb/?p=postgresql.git%3Ba=commit%3Bh=08fa47c4850cea32c3116665975bca219fbf2fe6http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172316.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169094.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00016.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00033.htmlhttp://www.debian.org/security/2015/dsa-3374http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.postgresql.org/about/news/1615/http://www.postgresql.org/docs/9.3/static/release-9-3-10.htmlhttp://www.postgresql.org/docs/9.4/static/release-9-4-5.htmlhttp://www.securityfocus.com/bid/77048http://www.securitytracker.com/id/1033775http://www.ubuntu.com/usn/USN-2772-1https://security.gentoo.org/glsa/201701-33http://git.postgresql.org/gitweb/?p=postgresql.git%3Ba=commit%3Bh=08fa47c4850cea32c3116665975bca219fbf2fe6http://lists.fedoraproject.org/pipermail/package-announce/2015-November/172316.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169094.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00016.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00033.htmlhttp://www.debian.org/security/2015/dsa-3374http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.postgresql.org/about/news/1615/http://www.postgresql.org/docs/9.3/static/release-9-3-10.htmlhttp://www.postgresql.org/docs/9.4/static/release-9-4-5.htmlhttp://www.securityfocus.com/bid/77048http://www.securitytracker.com/id/1033775http://www.ubuntu.com/usn/USN-2772-1https://security.gentoo.org/glsa/201701-33
2015-10-26
Published