Bug 1319810 (CVE-2016-3065) - CVE-2016-3065 postgresql: memory disclosure in pageinspect functions
Summary: CVE-2016-3065 postgresql: memory disclosure in pageinspect functions
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2016-3065
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1322984
Blocks: 1319814
TreeView+ depends on / blocked
 
Reported: 2016-03-21 15:05 UTC by Andrej Nemec
Modified: 2021-02-17 04:08 UTC (History)
6 users (show)

Fixed In Version: postgresql 9.5.2
Clone Of:
Environment:
Last Closed: 2016-03-31 20:44:03 UTC
Embargoed:


Attachments (Terms of Use)

Description Andrej Nemec 2016-03-21 15:05:01 UTC
A vulnerability was found in a way PostgreSQL uses pageinspect functions. Certain function arguments crashed the server or disclosed a few bytes of server memory. The viability of attacks that arrange for presence of confidential information in the disclosed bytes was not ruled out. This affects only databases that have used "CREATE EXTENSION pageinspect".

Comment 1 Andrej Nemec 2016-03-21 15:05:10 UTC
Acknowledgments:

Name: the PostgreSQL project
Upstream: Andreas Seltenreich

Comment 2 Andrej Nemec 2016-03-31 14:49:56 UTC
External references:

http://www.postgresql.org/about/news/1656/

Comment 5 Tomas Hoger 2016-03-31 20:44:03 UTC
Only PostgreSQL 9.5 was affected, which is not yet part of any Red Hat product.


Note You need to log in before you can comment on or make changes to this bug.