CVE-2016-0773
published 2016-02-17CVE-2016-0773: PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
6.95%
93.4th percentile
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regular expression.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| postgresql | postgresql | <= 9.1.19 | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
postgresql: case insensitive range handling integer overflow leading to buffer overflow
vendor_redhat·2016-02-11·CVSS 7.5
CVE-2016-0773 [HIGH] CWE-190 postgresql: case insensitive range handling integer overflow leading to buffer overflow
postgresql: case insensitive range handling integer overflow leading to buffer overflow
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regular expression.
An integer overflow flaw, leading to a heap-based buffer overflow, was found in the PostgreSQL handling code for regular expressions. A remote attacker could use a specially crafted regular expression to cause PostgreSQL to crash or possibly execute arbitrary code.
Package: postgresql (CloudForms Management Engine 5) - Affected
Package: postgresql92-postgresql (CloudForms Management Engine 5) - Affected
Package: postgresql (Red Hat E
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2016-02-11·CVSS 8.8
CVE-2016-0766 [HIGH] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: PostgreSQL could be made to crash or run programs if it handled specially
crafted data.
It was discovered that PostgreSQL incorrectly handled certain regular
expressions. A remote attacker could possibly use this issue to cause
PostgreSQL to crash, resulting in a denial of service. (CVE-2016-0773)
It was discovered that PostgreSQL incorrectly handled certain configuration
settings (GUCS) for users of PL/Java. A remote attacker could possibly use
this issue to escalate privileges. (CVE-2016-0766)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart PostgreSQL to
make all the necessary changes.
GHSA
GHSA-6p6w-jmg5-8cvx: PostgreSQL before 9
ghsa_unreviewed·2022-05-17
CVE-2016-0773 [HIGH] CWE-119 GHSA-6p6w-jmg5-8cvx: PostgreSQL before 9
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regular expression.
OSV
CVE-2016-0773: PostgreSQL before 9
osv·2016-02-11·CVSS 7.5
CVE-2016-0773 [HIGH] CVE-2016-0773: PostgreSQL before 9
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regular expression.
OSV
postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
osv·2016-02-11·CVSS 8.8
CVE-2016-0773 [HIGH] postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
It was discovered that PostgreSQL incorrectly handled certain regular
expressions. A remote attacker could possibly use this issue to cause
PostgreSQL to crash, resulting in a denial of service. (CVE-2016-0773)
It was discovered that PostgreSQL incorrectly handled certain configuration
settings (GUCS) for users of PL/Java. A remote attacker could possibly use
this issue to escalate privileges. (CVE-2016-0766)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-0773 postgresql: buffer overrun in regular expression processing [fedora-all]
bugzilla·2016-02-11·CVSS 7.5
CVE-2016-0773 [HIGH] CVE-2016-0773 postgresql: buffer overrun in regular expression processing [fedora-all]
CVE-2016-0773 postgresql: buffer overrun in regular expression processing [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2016-0773 postgresql: case insensitive range handling integer overflow leading to buffer overflow
bugzilla·2016-02-02·CVSS 7.5
CVE-2016-0773 [HIGH] CVE-2016-0773 postgresql: case insensitive range handling integer overflow leading to buffer overflow
CVE-2016-0773 postgresql: case insensitive range handling integer overflow leading to buffer overflow
A vulnerability was found in a way postgresql processes specially crafted regular expressions.
Purpose-crafted regular expressions elicited an integer overflow when
computing a heap allocation size, and the server proceeded to write past the
end of the undersized buffer. This could reliably crash the server, and we
have not ruled out the viability of attacks that lead to privilege escalation.
If an application accepts arbitrary regular expressions from its users, they
can exploit this without otherwise having access to query the database.
Acknowledgements:
Red Hat would like to thank PostgreSQL upstream for reporting this issue. Upstream acknowledges Tom Lane and Greg Stark as the orig
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177820.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177878.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00049.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00056.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1060.htmlhttp://www.debian.org/security/2016/dsa-3475http://www.debian.org/security/2016/dsa-3476http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.postgresql.org/about/news/1644/http://www.postgresql.org/docs/current/static/release-9-1-20.htmlhttp://www.postgresql.org/docs/current/static/release-9-2-15.htmlhttp://www.postgresql.org/docs/current/static/release-9-3-11.htmlhttp://www.postgresql.org/docs/current/static/release-9-4-6.htmlhttp://www.postgresql.org/docs/current/static/release-9-5-1.htmlhttp://www.securityfocus.com/bid/83184http://www.securitytracker.com/id/1035005http://www.ubuntu.com/usn/USN-2894-1https://kc.mcafee.com/corporate/index?page=content&id=SB10152https://puppet.com/security/cve/CVE-2016-0773https://security.gentoo.org/glsa/201701-33http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177820.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/177878.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00049.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00056.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1060.htmlhttp://www.debian.org/security/2016/dsa-3475http://www.debian.org/security/2016/dsa-3476http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.postgresql.org/about/news/1644/http://www.postgresql.org/docs/current/static/release-9-1-20.htmlhttp://www.postgresql.org/docs/current/static/release-9-2-15.htmlhttp://www.postgresql.org/docs/current/static/release-9-3-11.htmlhttp://www.postgresql.org/docs/current/static/release-9-4-6.htmlhttp://www.postgresql.org/docs/current/static/release-9-5-1.htmlhttp://www.securityfocus.com/bid/83184http://www.securitytracker.com/id/1035005http://www.ubuntu.com/usn/USN-2894-1https://kc.mcafee.com/corporate/index?page=content&id=SB10152https://puppet.com/security/cve/CVE-2016-0773https://security.gentoo.org/glsa/201701-33
2016-02-17
Published