Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-0063

Overview

Vulnerability Score 6.5 6.5
CVE Id CVE-2014-0063
Last Modified 24 Oct 2014 03:05:47
Published 31 Mar 2014 10:58:15
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication SINGLE_INSTANCE

CVE-2014-0063

Summary

Multiple stack-based buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via vectors related to an incorrect MAXDATELEN constant and datetime values involving (1) intervals, (2) timestamps, or (3) timezones, a different vulnerability than CVE-2014-0065.

Vulnerable Systems

Application

  • Postgresql 8.4.1

  • Postgresql 8.4.10

  • Postgresql 8.4.11

  • Postgresql 8.4.12

  • Postgresql 8.4.13

  • Postgresql 8.4.14

  • Postgresql 8.4.15

  • Postgresql 8.4.16

  • Postgresql 8.4.17

  • Postgresql 8.4.18

  • Postgresql 8.4.19

  • Postgresql 8.4.2

  • Postgresql 8.4.3

  • Postgresql 8.4.4

  • Postgresql 8.4.5

  • Postgresql 8.4.6

  • Postgresql 8.4.7

  • Postgresql 8.4.8

  • Postgresql 8.4.9

  • Postgresql 9.0

  • Postgresql 9.0.1

  • Postgresql 9.0.10

  • Postgresql 9.0.11

  • Postgresql 9.0.12

  • Postgresql 9.0.13

  • Postgresql 9.0.14

  • Postgresql 9.0.15

  • Postgresql 9.0.2

  • Postgresql 9.0.3

  • Postgresql 9.0.4

  • Postgresql 9.0.5

  • Postgresql 9.0.6

  • Postgresql 9.0.7

  • Postgresql 9.0.8

  • Postgresql 9.0.9

  • Postgresql 9.1

  • Postgresql 9.1.1

  • Postgresql 9.1.10

  • Postgresql 9.1.11

  • Postgresql 9.1.2

  • Postgresql 9.1.3

  • Postgresql 9.1.4

  • Postgresql 9.1.5

  • Postgresql 9.1.6

  • Postgresql 9.1.7

  • Postgresql 9.1.8

  • Postgresql 9.1.9

  • Postgresql 9.2

  • Postgresql 9.2.1

  • Postgresql 9.2.2

  • Postgresql 9.2.3

  • Postgresql 9.2.4

  • Postgresql 9.2.5

  • Postgresql 9.2.6

  • Postgresql 9.3

  • Postgresql 9.3.1

  • Postgresql 9.3.2


References

CONFIRM - https://github.com/postgres/postgres/commit/4318daecc959886d001a6e79c6ea853e8b1dfb4b

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=1065226

CONFIRM - http://www.postgresql.org/support/security/

CONFIRM - http://www.postgresql.org/about/news/1506/

DEBIAN - DSA-2865

DEBIAN - DSA-2864

CONFIRM - http://wiki.postgresql.org/wiki/20140220securityrelease

REDHAT - RHSA-2014:0469

CONFIRM - http://support.apple.com/kb/HT6448

CONFIRM - https://support.apple.com/kb/HT6536

APPLE - APPLE-SA-2014-10-16-3


Last Updated: 27 May 2016 11:04:48