Bug 1270306 (CVE-2015-5288)
| Summary: | CVE-2015-5288 postgresql: limited memory disclosure flaw in crypt() | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Adam Mariš <amaris> | 
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | 
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | bkearney, databases-maint, devrim, hhorak, jdobes, jmlich83, jorton, jrusnack, jstanek, meissner, mike, mmaslano, praiskup, santony, scorneli, tgl, thomas, tlestach, weli | 
| Target Milestone: | --- | Keywords: | Security | 
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | postgresql 9.4.5, postgresql 9.3.10, postgresql 9.2.14, postgresql 9.1.19, postgresql 9.0.23 | Doc Type: | Bug Fix | 
| Doc Text: | A memory leak error was discovered in the crypt() function of the pgCrypto extension. An authenticated attacker could possibly use this flaw to disclose a limited amount of the server memory. | Story Points: | --- | 
| Clone Of: | Environment: | ||
| Last Closed: | 2019-06-08 02:43:55 UTC | Type: | --- | 
| Regression: | --- | Mount Type: | --- | 
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1270314, 1270315, 1273440, 1273441, 1273442, 1273443, 1273445, 1273446, 1273780, 1273781, 1274649 | ||
| Bug Blocks: | 1270313 | ||
| 
        
          Description
        
        
          Adam Mariš
        
        
        
        
        
          2015-10-09 14:42:18 UTC
        
       Created mingw-postgresql tracking bugs for this issue: Affects: fedora-all [bug 1270315] Created postgresql tracking bugs for this issue: Affects: fedora-all [bug 1270314] This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2015:2081 https://rhn.redhat.com/errata/RHSA-2015-2081.html This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 6 Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS Via RHSA-2015:2077 https://rhn.redhat.com/errata/RHSA-2015-2077.html This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 6 Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS Via RHSA-2015:2083 https://rhn.redhat.com/errata/RHSA-2015-2083.html This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2015:2078 https://rhn.redhat.com/errata/RHSA-2015-2078.html |