postgresql: buffer overflow flaws in replacement *printf() functions
Published Jan 27, 2020
8.8
HIGHCVSS 3.1
EPSS 5.14%
Description
Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a Windows system, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a floating point number with a large precision, as demonstrated by using the to_char function.
Affected products
-
- Version 9.1.x before 9.1.15StatusaffectedConstraints-
- Version 9.2.x before 9.2.10StatusaffectedConstraints-
- Version 9.3.x before 9.3.6StatusaffectedConstraints-
- Version 9.4.x before 9.4.1StatusaffectedConstraints-
- Version before 9.0.19StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| PostgreSQL Global Development Group | PostgreSQL | n/a |
|
Configuration 1
- < 9.0.19
- ≥ 9.1.0 · < 9.1.15
- ≥ 9.2.0 · < 9.2.10
- ≥ 9.3.0 · < 9.3.6
- ≥ 9.4.0 · < 9.4.1
Configuration 2
- 7.0
- 8.0
No data.
CloudForms Management Engine 5
postgresql
Not affected
CloudForms Management Engine 5
postgresql92-postgresql
Not affected
Red Hat Enterprise Linux 5
postgresql
Not affected
Red Hat Enterprise Linux 5
postgresql84
Not affected
Red Hat Enterprise Linux 6
postgresql
Not affected
Red Hat Enterprise Linux 7
postgresql
Not affected
Red Hat Satellite 5
postgresql92
Not affected
Red Hat Software Collections
postgresql92-postgresql
Not affected
Red Hat Software Collections
rh-postgresql94-postgresql
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | postgresql | Not affected | n/a |
| CloudForms Management Engine 5 | postgresql92-postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 5 | postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 5 | postgresql84 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | postgresql | Not affected | n/a |
| Red Hat Enterprise Linux 7 | postgresql | Not affected | n/a |
| Red Hat Satellite 5 | postgresql92 | Not affected | n/a |
| Red Hat Software Collections | postgresql92-postgresql | Not affected | n/a |
| Red Hat Software Collections | rh-postgresql94-postgresql | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue does not affect the version of the postgresql package shipped in Red Hat Enterprise Linux 5, 6, and 7 because it does not use the vulnerable implementation of the snprintf() function provided by postgresql; the glibc implementation of this function, which is not vulnerable to this issue, is used instead.
References (11)
- http://www.debian.org/security/2015/dsa-3155 x_refsource_CONFIRMThird Party Advisory
- http://www.postgresql.org/about/news/1569/ x_refsource_CONFIRMVendor Advisory
- http://www.postgresql.org/docs/9.4/static/release-9-4-1.html x_refsource_CONFIRMRelease NotesVendor Advisory
- http://www.postgresql.org/docs/current/static/release-9-0-19.html x_refsource_CONFIRMRelease NotesVendor Advisory
- http://www.postgresql.org/docs/current/static/release-9-1-15.html x_refsource_CONFIRMRelease NotesVendor Advisory
- http://www.postgresql.org/docs/current/static/release-9-2-10.html x_refsource_CONFIRMRelease NotesVendor Advisory
- http://www.postgresql.org/docs/current/static/release-9-3-6.html x_refsource_CONFIRMRelease NotesVendor Advisory
- https://access.redhat.com/security/cve/CVE-2015-0242 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1188688 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2015-0242
- https://www.cve.org/CVERecord?id=CVE-2015-0242
| Link | Providers | Tags |
|---|---|---|
| http://www.debian.org/security/2015/dsa-3155 | x_refsource_CONFIRMThird Party Advisory | |
| http://www.postgresql.org/about/news/1569/ | x_refsource_CONFIRMVendor Advisory | |
| http://www.postgresql.org/docs/9.4/static/release-9-4-1.html | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| http://www.postgresql.org/docs/current/static/release-9-0-19.html | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| http://www.postgresql.org/docs/current/static/release-9-1-15.html | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| http://www.postgresql.org/docs/current/static/release-9-2-10.html | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| http://www.postgresql.org/docs/current/static/release-9-3-6.html | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2015-0242 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1188688 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2015-0242 | ||
| https://www.cve.org/CVERecord?id=CVE-2015-0242 |
Change history (0)
No recorded changes yet.