본문 바로가기

취약점 정보1

PostgreSQL class D vulnerability in contrib module: CVE-2014-0066

728x90

PostgreSQL class D vulnerability in contrib module: CVE-2014-0066

SeverityCVSSPublishedAddedModified
4(AV:N/AC:L/Au:S/C:N/I:N/A:P)March 31, 2014April 01, 2014April 01, 2014

Description

The chkpass extension in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly check the return value of the crypt library function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors.

Solution

Related Vulnerabilities


728x90