A flaw was found in the way PostgreSQL handled certain errors that were generated during protocol synchronization. An authenticated database user could use this flaw to inject queries into an existing connection.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 1 | postgresql8 | 2015-04-15 21:47 | ALAS-2015-503 |
Amazon Linux 1 | postgresql92 | 2015-03-13 02:37 | ALAS-2015-492 |
Amazon Linux 1 | postgresql93 | 2015-02-25 20:34 | ALAS-2015-485 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv2 | 2.1 | AV:N/AC:H/Au:S/C:N/I:P/A:N |
NVD | CVSSv2 | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
NVD | CVSSv3 | 9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |