USN-2772-1
Dashboard / Vulnerabilities / USN-2772-1
USN-2772-1
Summary: postgresql-9.1, postgresql-9.3, postgresql-9.4 vulnerabilities
Details: Josh Kupershmidt discovered the pgCrypto extension could expose several bytes of server memory if the crypt() function was provided a too-short salt. An attacker could use this flaw to read private data. (CVE-2015-5288) Oskari Saarenmaa discovered that the json and jsonb handlers could exhaust available stack space. An attacker could use this flaw to perform a denial of service attack. This issue only affected Ubuntu 14.04 LTS and Ubuntu 15.04. (CVE-2015-5289)
References: https://ubuntu.com/security/notices/USN-2772-1, https://ubuntu.com/security/CVE-2015-5288, https://ubuntu.com/security/CVE-2015-5289
Affected packages
Package
Name: postgresql-9.3
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
