Bug 1270312 (CVE-2015-5289)
Summary: | CVE-2015-5289 postgresql: stack overflow DoS when parsing json or jsonb inputs | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Adam Mariš <amaris> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | bkearney, databases-maint, devrim, hhorak, jdobes, jmlich83, jorton, jrusnack, jstanek, meissner, mike, mmaslano, praiskup, tgl, thomas, tlestach, weli |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | postgresql 9.4.5, postgresql 9.3.10, postgresql 9.2.14, postgresql 9.1.19, postgresql 9.0.23 | Doc Type: | Bug Fix |
Doc Text: |
A stack overflow flaw was discovered in the way the PostgreSQL core server processed certain JSON or JSONB input. An authenticated attacker could possibly use this flaw to crash the server backend by sending specially crafted JSON or JSONB input.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2019-06-08 02:43:57 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1270314, 1270315, 1273440, 1273441, 1273442, 1273443, 1273780, 1273781, 1274649 | ||
Bug Blocks: | 1270313 |
Description
Adam Mariš
2015-10-09 14:50:21 UTC
Created mingw-postgresql tracking bugs for this issue: Affects: fedora-all [bug 1270315] Created postgresql tracking bugs for this issue: Affects: fedora-all [bug 1270314] This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 6 Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS Via RHSA-2015:2077 https://rhn.redhat.com/errata/RHSA-2015-2077.html This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 6 Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS Via RHSA-2015:2083 https://rhn.redhat.com/errata/RHSA-2015-2083.html This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2015:2078 https://rhn.redhat.com/errata/RHSA-2015-2078.html |