CVE-2017-15098
published 2017-11-22CVE-2017-15098: Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x…
PriorityP344high8.1CVSS 3.0
AVNACLPRLUINSUCHINAH
EPSS
3.72%
88.6th percentile
Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.
Affected
66 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
| postgresql | postgresql | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
osv8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4r9v-fq66-c5gx: Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10
ghsa_unreviewed·2022-05-14
CVE-2017-15098 [HIGH] CWE-200 GHSA-4r9v-fq66-c5gx: Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10
Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.
OSV
CVE-2017-15098: Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10
osv·2017-11-22·CVSS 8.1
CVE-2017-15098 [HIGH] CVE-2017-15098: Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10
Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.
OSV
postgresql-9.3, postgresql-9.5, postgresql-9.6 vulnerabilities
osv·2017-11-14·CVSS 8.1
CVE-2017-15098 [HIGH] postgresql-9.3, postgresql-9.5, postgresql-9.6 vulnerabilities
postgresql-9.3, postgresql-9.5, postgresql-9.6 vulnerabilities
David Rowley discovered that PostgreSQL incorrectly handled memory when
processing certain JSON functions. A remote attacker could possibly use
this issue to obtain sensitive information. (CVE-2017-15098)
Dean Rasheed discovered that PostgreSQL incorrectly enforced SELECT
privileges when processing INSERT ... ON CONFLICT DO UPDATE commands. A
remote attacker could possibly use this issue to obtain sensitive
information. This issue only affected Ubuntu 16.04 LTS, Ubuntu 17.04 and
Ubuntu 17.10.
Ubuntu
PostgreSQL vulnerabilities
vendor_ubuntu·2017-11-14·CVSS 8.1
CVE-2017-15098 [HIGH] PostgreSQL vulnerabilities
Title: PostgreSQL vulnerabilities
Summary: Several security issues were fixed in PostgreSQL.
David Rowley discovered that PostgreSQL incorrectly handled memory when
processing certain JSON functions. A remote attacker could possibly use
this issue to obtain sensitive information. (CVE-2017-15098)
Dean Rasheed discovered that PostgreSQL incorrectly enforced SELECT
privileges when processing INSERT ... ON CONFLICT DO UPDATE commands. A
remote attacker could possibly use this issue to obtain sensitive
information. This issue only affected Ubuntu 16.04 LTS, Ubuntu 17.04 and
Ubuntu 17.10.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart PostgreSQL to
make all the necessary changes.
Red Hat
postgresql: Memory disclosure in JSON functions
vendor_redhat·2017-11-09·CVSS 8.1
CVE-2017-15098 [HIGH] CWE-200 postgresql: Memory disclosure in JSON functions
postgresql: Memory disclosure in JSON functions
Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.
Statement: This issue affects the versions of rh-postgresql94-postgresql, rh-postgresql95-postgresql, and rh-postgresql96-postgresql as shipped with Red Hat Software Collections 3. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: postgresql (Red Hat Enterprise Linux 5) - Not aff
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/101781http://www.securitytracker.com/id/1039752https://access.redhat.com/errata/RHSA-2018:2511https://access.redhat.com/errata/RHSA-2018:2566https://www.debian.org/security/2017/dsa-4027https://www.debian.org/security/2017/dsa-4028https://www.postgresql.org/about/news/1801/https://www.postgresql.org/support/security/http://www.securityfocus.com/bid/101781http://www.securitytracker.com/id/1039752https://access.redhat.com/errata/RHSA-2018:2511https://access.redhat.com/errata/RHSA-2018:2566https://www.debian.org/security/2017/dsa-4027https://www.debian.org/security/2017/dsa-4028https://www.postgresql.org/about/news/1801/https://www.postgresql.org/support/security/
2017-11-22
Published